OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104059

HIGH · CVSS 8.1 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-01 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Lektor versions 3.3.14 and 3.4.0b15 are vulnerable to a cross-site request forgery (CSRF) flaw in the admin API, allowing unauthenticated attackers to execute state-changing actions without proper validation mechanisms. This vulnerability can be exploited to manipulate content, delete records, and disclose sensitive data through malicious web pages. Organizations using these Lektor versions, particularly those with exposed admin APIs, should prioritize immediate remediation to mitigate potential data breaches and unauthorized actions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104059
Severity
HIGH
CVSS
8.1
EPSS
0.14%

Original NVD Description

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.