CVE-2026-101093
Deferred Deferred - Pending Action

Cross-Site Request Forgery in Cotonti Admin Panel

Vulnerability report for CVE-2026-101093, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulnCheck

Description

Cotonti through 1.0.0 contains a cross-site request forgery vulnerability in admin.users.php that allows attackers to delete user groups without token verification. Attackers can craft malicious links or pages that trick authenticated administrators into deleting custom groups and their associated permissions by riding the administrator's session.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cotonti cotonti to 1.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

Cotonti through 1.0.0 has a cross-site request forgery (CSRF) vulnerability in admin.users.php. This flaw allows attackers to delete user groups without proper token verification. Attackers can trick authenticated administrators into deleting custom groups and their permissions by exploiting the administrator's active session.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized deletions of user groups in Cotonti's admin.users.php. Monitor server logs for suspicious POST requests to admin.users.php with actions like 'delete_group'. Look for missing CSRF tokens in these requests. Check if custom user groups were unexpectedly removed.

Impact Analysis

If you are an administrator using Cotonti, this vulnerability could allow attackers to delete your custom user groups and associated permissions without your knowledge. This could disrupt access control, remove critical user roles, and potentially lock users out of the system.

Compliance Impact

This vulnerability could impact compliance by allowing unauthorized changes to user permissions, potentially violating access control requirements in GDPR and HIPAA. Unauthorized deletion of user groups may lead to improper data access or loss of audit trails.

Mitigation Strategies

Immediately update Cotonti to the latest version beyond 1.0.0 to patch the CSRF flaw. If an update isn't available, disable the admin.users.php functionality or restrict access to it via server rules. Implement strict session timeouts and require re-authentication for sensitive actions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-101093. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart