CVE-2025-26748
CVSS 3.1 Score 8.1 of 10 (high)
Details
Summary
CVE-2025-26748 is a Cross-Site Request Forgery (CSRF) vulnerability identified in LOOS,Inc.'s Arkhe application. This issue enables an attacker to manipulate a victim's web session, leading to unauthorized Local File Inclusion in Arkhe versions from n/a to 3.11.0. An attacker can exploit this vulnerability by tricking the victim into clicking a malicious link, potentially granting the attacker access to sensitive files or further compromising the system. It is essential for users to apply the necessary patches to mitigate this risk and protect their systems from potential attacks.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.