CVE-2026-67993

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f contains a login cross-site request forgery issue in the static credentials callback.

  • Published Sep 29, 2026
  • CVSS 8.8 high
  • 0.1% chance of exploitation in the next 30 days (EPSS)

CVE-2026-67993 at the National Vulnerability Database