CVE-2026-67993
Received Received - Intake

Login CSRF in Basecamp Upright Static Credentials

Vulnerability report for CVE-2026-67993, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: MITRE

Description

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
basecamp upright *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a login cross-site request forgery (CSRF) issue in the static credentials callback of the basecamp/upright project at a specific commit. CSRF tricks users into submitting unauthorized commands via their authenticated session. The SessionsController lacks proper CSRF protection for the create action, allowing attackers to forge login requests.

Detection Guidance

Check the sessions_controller.rb file in your Upright installation for the create action. Look for skip_forgery_protection being used, which disables CSRF protection. Verify if the SessionsController has skip_before_action :authenticate_user for new and create actions.

Impact Analysis

An attacker could trick an authenticated user into unknowingly triggering a login request, potentially allowing unauthorized access to the system. This could lead to session hijacking, data manipulation, or further exploitation of the application's functionality.

Compliance Impact

This vulnerability could lead to unauthorized access, violating data protection principles in GDPR and HIPAA. GDPR requires protecting personal data, while HIPAA mandates secure access controls. A CSRF flaw may result in non-compliance, potential fines, and loss of trust due to unauthorized data exposure.

Mitigation Strategies

Remove skip_forgery_protection from the create action in sessions_controller.rb. Ensure CSRF protection is enabled for all authentication-related actions. Review and update authentication mechanisms to enforce proper session management.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-67993. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart