Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to delete commands individually via '/delete_command?sid=', using the 'cid' parameter.
History

Wed, 28 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
Description Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to delete commands individually via '/delete_command?sid=', using the 'cid' parameter.
Title Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server
First Time appeared Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
Weaknesses CWE-352
CPEs cpe:2.3:a:flexense:disk_pulse_enterprise:v10.4.18:*:*:*:*:*:*:*
cpe:2.3:a:flexense:sync_breeze_enterprise_server:v10.4.18:*:*:*:*:*:*:*
Vendors & Products Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2026-01-28T11:52:35.782Z

Updated: 2026-01-28T15:45:40.967Z

Reserved: 2025-09-23T10:22:34.912Z

Link: CVE-2025-59892

cve-icon Vulnrichment

Updated: 2026-01-28T15:45:37.778Z

cve-icon NVD

Status : Received

Published: 2026-01-28T12:15:50.690

Modified: 2026-01-28T12:15:50.690

Link: CVE-2025-59892

cve-icon Redhat

No data.