CVE-2026-4590 Details
Description
A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the component loginSubmit API. Performing a manipulation of the argument third results in cross-site request forgery. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
A cross-site request forgery (CSRF) vulnerability has been identified in Kalcaddle Kodbox version 1.64. The issue arises in the loginSubmit API, specifically within an unknown function of the file '/workspace/source-code/plugins/oauth/controller/bind/index.class.php'. The vulnerability allows remote exploitation, although it requires a high level of complexity to execute. The exploitation process has been made public and is available as a proof-of-concept.
The vulnerability can be addressed by rejecting raw client data in the 'third' argument, validating all OAuth identities through trusted server-to-server processes, enforcing CSRF protection and POST-only requirements on binding operations, and implementing strong verification and auditing for UnionID bindings.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Mar 23, 2026CISA-ADP
Assessed Mar 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://vuldb.com/?ctiid.352426 | [email protected] | Content WallTechnical Description |
| https://vuldb.com/?id.352426 | [email protected] | AdvisoryExploitPartial Content |
| https://vuldb.com/?submit.775469 | [email protected] | Technical Description |
| https://vulnplus-note.wetolink.com/share/IJW1LjsyomCQ | [email protected] | Broken Link |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
| CWE-862 | Missing Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kalcaddle kodbox | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Mar 23, 2026 | New CVE Received | [email protected] |
Volerion