CVE-2026-32989Disclosure(precurio / intranet_portal)

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch precurio intranet_portal systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests to a profile update endpoint handling file uploads. Attackers can exploit this to upload executable files to web-accessible locations, leading to arbitrary code execution in the context of the web server.

0.5/ 10 priority

Sources & remediation

Other references
Weakness type (CWE)
CWE-352CWE-434

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • intranet_portal

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 4 mentions (2026-03-20); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
intranet_portal

1 version affected across 1 product

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-03-20: 4Mentions · 2026-03-22: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 4Technical Details · 2026-03-22: 103-2003-22
Signal classification2 categories
Disclosure
480.0%
Patch
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-204
Disclosure3Patch1
2026-03-221
Disclosure1
Full discourse5 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-32989 Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests to a p… https://www.cve.org/CVERecord?id=CVE-2026-32989

    Post summary

    The post announces CVE-2026-32989, a CSRF vulnerability in Precurio Intranet Portal 4.4 that could trick authenticated users into submitting crafted requests; no PoC, exploit, or patch details are provided.

    0000073
    56.8K followersView on X
  • ナタリー 🌙@natalie_avfieb
    Disclosure

    Just dug into CVE-2026-32989 in Precurio 4.4: the CSRF on profile updates lets an attacker nudge an authenticated admin into sending a crafted request. Same-site cookies plus rotating tokens would have broken it. Cross-site defenses still earn their keep. #CVE2026 #infosec

    Post summary

    The post details a CSRF vulnerability in Precurio 4.4 that allows an attacker to prompt an authenticated admin to send crafted profile‑update requests, highlighting that same‑site cookies and rotating tokens would prevent exploitation.

    0000055
    89 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-32989 Cross-Site Request Forgery in Precurio Intranet Portal 4.4 Leading to Potential Code Execution https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-32989

    Post summary

    Disclosed vulnerability CVE-2026-32989 indicates a CSRF flaw in Precurio Intranet Portal 4.4 that could lead to code execution; no PoC, exploit, patch, or active exploitation details are provided.

    0000044
    4.0K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-32989 - High Precurio Intranet Portal 4.4 contains a cross-site request forgery vulnerability that allows attackers to induce authenticated users to submit crafted requests to a profile update endpoint ha... https://www.thehackerwire.com/vulnerability/CVE-2026-32989/ https://t.co/XibgKbhbch

    Post summary

    A link to a vulnerability page discloses that Precurio Intranet Portal 4.4 has a high‑severity CSRF flaw enabling attackers to trick authenticated users into sending crafted profile‑update requests.

    0000035
    138 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-32989: HIGH] Precurio Intranet Portal 4.4 has a CSRF vulnerability allowing attackers to manipulate authenticated users into executing malicious code. Upgrade for security.#cve,CVE-2026-32989,#cybersecurity https://cvefind.com/CVE-2026-32989

    Post summary

    Precurio Intranet Portal 4.4 suffers a high‑severity CSRF flaw that can enable malicious code execution by authenticated users, and the advisory urges an upgrade to mitigate the risk.

    0000040
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appprecuriointranet_portal4.4--

Explore more