CVE-2026-38934
High severity, CVSS 8.8. EPSS: 0.2% chance of exploitation in the next 30 days.
Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php
Published 2026-04-27. Last modified 2026-07-05.