Get real-time updates on Telegram
Verified
CVE-2026-103692: Frontend Dashboard 3.0.0 to before 3.0.5
Affected technology
Frontend Dashboard · 3.0.0 to before 3.0.5
Vendor not specified by the source
Description’s affected range: before 3.0.5 does not perform any authorisation or nonce check on actions available to unauthenticated users that call an attacker-chosen PHP function or class method with the request data
Component: Not specified by the source
What an attacker can do
Unauthenticated users can take over any account, including administrators.
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-08 08:50:52.119177+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 08:49:39.219831+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2026-103692.html