CVE-2026-67366Patch

LOWCVSS 5.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Joomla Extension - icagenda.com - CSRF on frontend registration actions in iCagenda < 2.0.0-4.0.11 - Multiple state changing operations in the frontend are callable without a CSRF token check.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-08-13); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-13: 1Mentions · 2026-08-15: 1Patch / Workaround · 2026-08-13: 1Technical Details · 2026-08-13: 1Technical Details · 2026-08-15: 108-1308-15
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-08-131
Patch1
2026-08-151
Disclosure1
Full discourse2 posts
  • CyStack@CyStackSecurity
    Patch

    3 vulnerabilities in RabbitMQ, the open-source message broker widely used in microservices architectures, finance, and e-commerce systems. CVE-2026-67415: Atom exhaustion via the Shovel plugin, pushing the broker into prolonged DoS, requires a restart. CVE-2026-67366: The Federation plugin skips vhost permission checks, allowing cross-tenant access. CVE-2026-67408: Super Streams exhausts resources before the permission check, hanging the node or causing DoS. Patches are available. Found by CyStack researchers. Details at https://cystack.net/disclosures #CyStack #CyberSecurity #Vulnerability #RabitMQ #InfoSec

    Post summary

    Three RabbitMQ vulnerabilities—CVE‑2026‑67415, CVE‑2026‑67366, and CVE‑2026‑67408—have been disclosed, allowing DoS and cross‑tenant access; patches are already available.

    01020101
    3.7K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-67366 CSRF Vulnerability in iCagenda Frontend Registration Actions Below 2.0.0-4.0.11 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-67366

    Post summary

    The post announces a CSRF vulnerability in iCagenda front‑end registration actions for versions below 2.0.0-4.0.11, providing basic technical details but no PoC, exploit, or patch information.

    00000133
    4.1K followersView on X

Explore more