Cross-site request forgery in Emlog Pro - CVE-2026-73847
Published: August 15, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary SQL against the application database and take over an administrator account.
The vulnerability exists due to cross-site request forgery in the AI Assistant execute_tool endpoint when processing a forged cross-site request delivered to a logged-in administrator. A remote attacker can trick the victim into loading an attacker-controlled page to execute arbitrary SQL against the application database and take over an administrator account.
User interaction is required, and cross-site delivery succeeds only during a narrow window shortly after the administrator logs in.