
CVE-2026-12593 The implementation of an internal and undocumented Dashboard API endpoint (POST /api/users/~/{user}/tokens) forgot to ensure an HTTP request for creating an API Token… https://www.cve.org/CVERecord?id=CVE-2026-12593
Post summary
The text discloses CVE-2026-12593, detailing that an undocumented API endpoint accepts token creation requests without proper HTTP validation.


