What is CVE-2026-73482?
CVE-2026-73482 is a CSRF vulnerability in phpList versions prior to 3.7.0-RC5. The administrator deletion action in lists/admin/admins.php is triggered via an unprotected GET request without a CSRF token. Users should immediately upgrade to version 3.7.0-RC5 or later.
Azərbaycanca: CVE-2026-73482 phpList-in 3.7.0-RC5-dən əvvəlki versiyalarında CSRF zəifliyidir. lists/admin/admins.php faylında administrator silmə əməliyyatı, qorunmayan GET sorğusu vasitəsilə həyata keçirilir. İstifadəçilər ən qısa zamanda 3.7.0-RC5 və ya daha yüksək versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-352; shared vendor: phpList
FAQ2
Which software product is affected by CVE-2026-73482?
The CVE-2026-73482 vulnerability affects phpList versions prior to 3.7.0-RC5.
What should be done to mitigate this CSRF vulnerability in phpList?
Users should immediately upgrade phpList to version 3.7.0-RC5 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.