CVE-2026-67993

High severity, CVSS 8.8. EPSS: 0.1% chance of exploitation in the next 30 days.

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.

Published 2026-09-29. Last modified 2026-09-30.