CVE-2026-18819

MEDIUM LAB

RackTables cross-site request forgery

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The project maintainer confirms: "[I]t seems plausible, in that RackTables does not at this time have any CSRF prevention. You may assign a CVE ID to this, but there is no guarantee it will be handled in urgent, or even timely, manner, or at all."

References (6)

Core 6
Core References
Vdb Entry vdb-entry
VDB-385818 | RackTables cross-site request forgery
https://vuldb.com/vuln/385818
Signature, Permissions Required signature permissions-required
VDB-385818 | CTI Indicators (IOB, IOC)
https://vuldb.com/vuln/385818/cti
Third Party Advisory third-party-advisory
CVE-2026-18819 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-18819
Third Party Advisory third-party-advisory
Submit #857970 | RackTables f14f64e65ac8d806b1f64a981acb3c6870eeae37 Cross-Site Request Forgery
https://vuldb.com/submit/857970

Scores

CVSS v3 4.3
EPSS 0.0016
EPSS Percentile 5.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull eclipse-temurin:17-jdk
docker pull gcr.io/oss-fuzz-base/base-builder

Details

CWE
CWE-352 CWE-862
Status published
Products (23)
None/RackTables 0.1
None/RackTables 0.10
None/RackTables 0.11
None/RackTables 0.12
None/RackTables 0.13
None/RackTables 0.14
None/RackTables 0.15
None/RackTables 0.16
None/RackTables 0.17
None/RackTables 0.18
... and 13 more
Published Aug 04, 2026
Tracked Since Aug 05, 2026