{"id":"UBUNTU-CVE-2026-67990","details":"basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager and Prometheus proxy controllers. An unauthenticated attacker can induce a logged-in user's browser to submit requests that are forwarded to enabled upstream write or management endpoints, such as creating an Alertmanager silence or requesting a Prometheus reload. The final impact depends on the APIs enabled by the upstream services.","modified":"2026-08-14T20:45:24.407350212Z","published":"2026-08-14T00:00:00Z","upstream":["CVE-2026-67990"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-67990"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-67990"},{"type":"REPORT","url":"https://gist.github.com/Zykis1024/cec690012eecac53f408e78d2b569f06"},{"type":"REPORT","url":"https://github.com/basecamp/upright"},{"type":"REPORT","url":"https://github.com/basecamp/upright/blob/efe4f2e5254ac6e57e45d2261804cca74dbbca3f/app/controllers/upright/alertmanager_proxy_controller.rb#L2"},{"type":"REPORT","url":"https://github.com/basecamp/upright/blob/efe4f2e5254ac6e57e45d2261804cca74dbbca3f/app/controllers/upright/prometheus_proxy_controller.rb#L2"}],"affected":[{"package":{"name":"at","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/at?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.13-2ubuntu2","3.1.14-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"at","binary_version":"3.1.14-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-67990.json"}},{"package":{"name":"at","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/at?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.16-1ubuntu1","3.1.18-2ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.1.18-2ubuntu1","binary_name":"at"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-67990.json"}},{"package":{"name":"at","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/at?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.20-3ubuntu1","3.1.20-3.1ubuntu1","3.1.20-3.1ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"at","binary_version":"3.1.20-3.1ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-67990.json"}},{"package":{"name":"at","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/at?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.23-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.1.23-1ubuntu1","binary_name":"at"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-67990.json"}},{"package":{"name":"at","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/at?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.1.23-1.1ubuntu3","3.2.5-1","3.2.5-1ubuntu1"],"ecosystem_specific":{"binaries":[{"binary_name":"at","binary_version":"3.2.5-1ubuntu1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-67990.json"}},{"package":{"name":"at","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/at?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.5-1ubuntu1","3.2.5-2.1ubuntu2","3.2.5-2.1ubuntu3"],"ecosystem_specific":{"binaries":[{"binary_name":"at","binary_version":"3.2.5-2.1ubuntu3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-67990.json"}},{"package":{"name":"at","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/at?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.2.5-2.2ubuntu1","3.2.5-2.2ubuntu2"],"ecosystem_specific":{"binaries":[{"binary_name":"at","binary_version":"3.2.5-2.2ubuntu2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-67990.json"}}],"schema_version":"1.9.0","severity":[{"type":"Ubuntu","score":"medium"}]}