CERT Polska disclosed CVE-2026-41875, a cross-site request forgery (CSRF) vulnerability affecting OpenSolution Quick.Cart through version 6.7.0. An attacker can induce an authenticated Quick.Cart administrator to visit a malicious website, which submits a forged POST request to the administrative configuration panel and changes the administrator login and password, enabling account takeover.
Quick.Cart’s existing CSRF control can reportedly be bypassed through manipulation of the Referer header, potentially leaving other application forms exposed to forged requests. CERT Polska coordinated disclosure following a report from Karol Czubernat; organizations should apply the patch for version 6.7 released on 9 November 2026 and verify that state-changing requests use robust anti-CSRF tokens rather than relying on Referer validation.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
Karol Czubernat reported CVE-2026-41875, a CSRF flaw affecting OpenSolution Quick.Cart through version 6.7.0, and CERT Polska participated in coordinated disclosure. The flaw can let a crafted site trigger an authenticated administrator to change administrator credentials by bypassing the product's Referer-based CSRF protection.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.