
🚨*CVE* CVE-2026-31954 Emlog is an open source website building system. In 2.6.6 and earlier, the delete_async action (asynchronous delete) lacks a call to LoginAuth::checkToken(), enabling… https://www.cve.org/CVERecord?id=CVE-2026-31954 ----- Traducción: CVE-2026-31954 Eml… http://infoflow.cloud`
Post summary
The tweet announces the discovery of CVE‑2026‑31954, describing a missing authentication check in Emlog’s delete_async action, but does not provide PoC, exploit code, active exploitation evidence, or a patch.

