QuickCMS version 6.8 contains a Cross-Site Request Forgery vulnerability (CVE-2026-1468)…
QuickCMS version 6.8 contains a Cross-Site Request Forgery vulnerability (CVE-2026-1468) affecting multiple endpoints with no CSRF protection implemented.
CERT Polska coordinated disclosure of CVE-2026-1468, a Cross-Site Request Forgery (CSRF) vulnerability affecting QuickCMS software. The vulnerability allows attackers to craft malicious websites that, when visited by authenticated victims, automatically send POST requests with the victim's privileges. The software lacks any CSRF protection mechanisms, making all forms within the application potentially exploitable.
Version 6.8 has been confirmed vulnerable through testing, though other versions remain untested and may also be affected. The vendor was notified early in the disclosure process but did not provide information about the vulnerability details or the full range of affected versions.
The vulnerability was responsibly reported by Michał Biesiada and coordinated through CERT Polska's vulnerability disclosure process. Organizations using QuickCMS should assess their exposure and monitor for vendor patches or mitigation guidance.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/03/CVE-2026-1468
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free