What is CVE-2026-64821?
CVE-2026-64821 is a Cross-Site Request Forgery (CSRF) vulnerability affecting djangoSIGE up to version 1.10. This flaw allows unauthenticated attackers to cancel sales or purchase orders on behalf of authenticated users by leveraging order-cancellation logic implemented in HTTP GET method handlers. It is recommended to update the application to the latest version to mitigate this issue.
Azərbaycanca: CVE-2026-64821 djangoSIGE 1.10 versiyasına qədər təsir edən Cross-Site Request Forgery (CSRF) zəifliyidir. Bu zəiflik autentifikasiya olunmamış hücumçulara HTTP GET sorğuları vasitəsilə autentifikasiyalı istifadəçilərin satış və ya alış sifarişlərini ləğv etməyə imkan yaradır. Təhlükəsizlik üçün tətbiqi ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-352
FAQ2
Which versions of djangoSIGE are affected by CVE-2026-64821?
This CSRF vulnerability affects all versions of the djangoSIGE application up to version 1.10.
What can an attacker do by exploiting CVE-2026-64821?
An unauthenticated attacker can cancel sales or purchase orders of authenticated users via HTTP GET requests.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.