CVE-2026-86182CWE-352CWE-862broken-access-controlcsrf

CVE-2026-86182

Medium · published September 6, 2026

CVSS v3.1
4.3
EPSS
0%
Percentile
5.3
In the wild
Unconfirmed
What it is

A vulnerability was determined in diem-project diem up to 5.1.3. This affects the function executeCommand of the file dmAdminPlugin/modules/dmConsole/actions/actions.class.php of the component dmConsole. This manipulation of the argument dm_command causes cross-site request forgery. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet.

The record
Technical detail
CVSS v3.1
4.3 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
CVSS v4.0
5.3 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
EPSS
0.00159 · 5.3th percentile
Weaknesses
CWE-352 · Cross-Site Request Forgery (CSRF); CWE-862 · Missing Authorization
Published
2026-09-06T13:17Z
References (6)
EPSS history
Timeline
  • 07 SEP 03:36Z
    EPSS moved — → 0%
    epss
  • 06 SEP 08:45Z
    diem-project diem dmConsole actions.class.php executeCommand cross-site request forgery
    cvelistv5