CVE-2026-32989 identifies a critical Cross-Site Request Forgery (CSRF) vulnerability within Precurio Intranet Portal version 4.4. This flaw enables attackers to trick authenticated users into submitting crafted requests to a profile update endpoint, allowing the upload of executable files to web-accessible locations. With a CVSS score of 8.8 HIGH, this vulnerability can lead to arbitrary code execution on the web server, significantly impacting confidentiality, integrity, and availability, though it requires user interaction. There is currently no evidence of active exploitation, and no public exploit code or modules are available. Community discussion and media coverage for this CVE remain minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.4CPE matchmatch criteria | cpe:2.3:a:precurio:intranet_portal:4.4:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.