PT-2026-21568 · Bludit · Bludit

Ryan Chan

·

Published

2026-02-23

·

Updated

2026-02-24

·

CVE-2026-27741

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Bludit version 3.16.1
Description The application lacks anti-CSRF tokens or request origin validation for administrative actions. An attacker can trick an authenticated administrator into visiting a malicious page, which silently submits crafted requests. This can lead to unauthorized plugin uninstallation via the /admin/uninstall-plugin/ endpoint or theme installation via the /admin/install-theme/ endpoint. Successful exploitation may result in loss of functionality, execution of untrusted code through malicious themes, and compromise of system integrity.
Recommendations Apply updates to address the issue in Bludit version 3.16.1.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-27741

Affected Products

Bludit