Feed/CVE-2026-63265
CVE-2026-63265HIGHCVSS 8.0

CVE-2026-63265

Published Jul 22, 2026·Updated Jul 27, 2026

NVD Description

Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free