Skip to main content
Vulnerability Database/CVE-2026-63000

CVE-2026-63000: REDAXO CMS CSRF Vulnerability

CVE-2026-63000 is a CSRF flaw in REDAXO content management system that lets attackers force admins to install malicious packages. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-63000 Overview

CVE-2026-63000 is a Cross-Site Request Forgery (CSRF) vulnerability [CWE-352] affecting REDAXO, a PHP-based content management system, in versions prior to 5.21.2. The rex_api_install_package_update handler in redaxo/src/addons/install/lib/api/api_package_update.php inherits the default false return from rex_api_function::requiresCsrfProtection() instead of enforcing a CSRF token. An unauthenticated attacker can trick a logged-in administrator's browser into issuing a package update request to the configured REDAXO package server. The forged request can alter installed addon code or disrupt site availability without administrator intent. The issue is resolved in REDAXO version 5.21.2.

Critical Impact

A successful exploit lets a remote attacker modify installed addon code on a REDAXO site by hijacking an authenticated administrator session, undermining site integrity and availability.

Affected Products

  • REDAXO CMS versions prior to 5.21.2
  • redaxo/src/addons/install/lib/api/api_package_update.php API endpoint
  • REDAXO installations relying on the default rex_api_function::requiresCsrfProtection() behavior

Discovery Timeline

  • 2026-09-23 - CVE-2026-63000 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-63000

Vulnerability Analysis

The flaw is a classic CSRF weakness in the REDAXO install addon's package update API. The rex_api_install_package_update class extends rex_api_function but does not override requiresCsrfProtection(), which returns false by default. As a result, the endpoint accepts state-changing requests without validating a CSRF token. An attacker hosting a malicious page can craft a request that, when loaded by an authenticated administrator, causes the administrator's browser to invoke a package update against the configured REDAXO package server. Because the request executes in the administrator's session context, it can install, replace, or update addon code on the target site.

Root Cause

The root cause is a missing CSRF protection declaration in the API handler. Any subclass of rex_api_function that performs state-changing actions must override requiresCsrfProtection() to return true. The package update handler did not, so the framework skipped token verification for that endpoint.

Attack Vector

Exploitation requires an authenticated REDAXO administrator to visit or render attacker-controlled content while logged in. The attacker crafts an HTML page, image tag, or auto-submitting form that triggers a request to the vulnerable endpoint. Successful abuse changes installed addon code or disrupts the site, and depending on which addon package is targeted, may lead to further compromise of the CMS instance.

php
         }
         return new rex_api_result($success, $message);
     }
+
+    protected function requiresCsrfProtection()
+    {
+        return true;
+    }
 }

Source: GitHub Commit a13abbf — the patch adds the requiresCsrfProtection() override so the framework enforces token validation on the package update API.

Detection Methods for CVE-2026-63000

Indicators of Compromise

  • Unexpected requests to rex_api_install_package_update in web server or REDAXO application logs, particularly those with Referer headers pointing to external domains.
  • Unplanned addon installations, updates, or file modifications under the REDAXO addon directories.
  • Administrator sessions issuing package update calls without a corresponding _csrf_token parameter.

Detection Strategies

  • Review REDAXO installations and confirm they are on version 5.21.2 or later; earlier versions are vulnerable by default.
  • Inspect access logs for POST or GET requests containing rex_api_install_package_update and correlate with administrator authentication events.
  • Audit installed addons against a known-good baseline to identify unauthorized changes to package code.

Monitoring Recommendations

  • Enable file integrity monitoring on the REDAXO addons/ directory to alert on unexpected changes.
  • Forward web server and application logs to a centralized analytics platform and alert on API calls originating from unusual referrers or user agents.
  • Track administrator session activity for state-changing API calls that lack CSRF tokens.

How to Mitigate CVE-2026-63000

Immediate Actions Required

  • Upgrade REDAXO to version 5.21.2 or later, which enforces CSRF protection on the package update API.
  • Rotate administrator credentials and invalidate active sessions if unauthorized package updates are suspected.
  • Restrict administrator access to trusted networks and require administrators to use dedicated browser profiles that do not visit untrusted content.

Patch Information

The fix is delivered in REDAXO 5.21.2 via pull request #6579 and commit a13abbf. Details are documented in GitHub Security Advisory GHSA-m8r3-22v6-g877. The patch overrides requiresCsrfProtection() in rex_api_install_package_update to return true.

Workarounds

  • If patching is not immediately possible, restrict access to the REDAXO backend using IP allowlisting or VPN-based access controls.
  • Configure the web server or a reverse proxy to reject requests to rex_api_install_package_update that lack an expected _csrf_token parameter.
  • Instruct administrators to log out of the REDAXO backend when not actively performing administrative tasks.
bash
# Example nginx rule to block unauthenticated CSRF attempts against the package update API
location /redaxo/index.php {
    if ($arg_rex_api_call = "install_package_update") {
        if ($arg__csrf_token = "") { return 403; }
    }
}

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.