CVE-2026-104059
Received Received - Intake

Cross-Site Request Forgery in Lektor Admin API

Vulnerability report for CVE-2026-104059, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: VulnCheck

Description

Lektor 3.3.14 and 3.4.0b15 contains a cross-site request forgery vulnerability in the admin API blueprint that allows unauthenticated attackers to perform state-changing actions by sending cross-origin requests without CSRF tokens, Origin/Referer validation, CORS configuration, or Host allowlisting. Attackers can exploit the newattachment, deleterecord, build, clean, and publish endpoints from a malicious web page to write arbitrary files, delete pages, wipe build output, trigger deployment publication, and via DNS rebinding reach read endpoints to disclose data.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
lektor lektor 3.3.14
lektor lektor 3.4.0b15

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104059 is a high-severity Cross-Site Request Forgery (CSRF) vulnerability in Lektor versions 3.3.14 and 3.4.0b15. It exists in the admin API blueprint and allows unauthenticated attackers to perform state-changing actions via cross-origin requests without proper CSRF protections. Exploitable endpoints include newattachment, deleterecord, build, clean, and publish.

Detection Guidance

To detect this CSRF vulnerability in Lektor, check if the admin API endpoints (/admin/api/*) are accessible without proper CSRF protections. Verify if requests to endpoints like newattachment, deleterecord, build, clean, or publish can be triggered without tokens or origin validation. Inspect server logs for unusual activity such as file writes, deletions, or rebuilds originating from unexpected sources.

Impact Analysis

Attackers can exploit this vulnerability to write arbitrary files, delete pages, wipe build output, trigger deployments, or access sensitive data through DNS rebinding. The impact includes potential loss of data integrity, confidentiality, and availability.

Mitigation Strategies

Immediately upgrade Lektor to a patched version if available. If no patch exists, disable the admin API endpoints or restrict access to trusted IPs. Implement CSRF tokens, validate Origin/Referer headers, and configure CORS properly. Change state-changing methods like publish from GET to POST to prevent CSRF attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104059. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart