Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to rename commands via '/rename_command?sid=', affecting the 'command_name' parameter.
History

Tue, 10 Feb 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Flexense diskpulse
Flexense syncbreeze
CPEs cpe:2.3:a:flexense:diskpulse:10.4.18:*:*:*:enterprise:*:*:*
cpe:2.3:a:flexense:syncbreeze:10.4.18:*:*:*:enterprise:*:*:*
Vendors & Products Flexense diskpulse
Flexense syncbreeze
Metrics cvssV3_1

{'score': 8.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Wed, 28 Jan 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 28 Jan 2026 12:00:00 +0000

Type Values Removed Values Added
Description Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18. An authenticated user could cause another user to perform unwanted actions within the application they are logged into. This vulnerability is possible due to the lack of proper CSRF token implementation. Among other things, it is possible, using a POST request to rename commands via '/rename_command?sid=', affecting the 'command_name' parameter.
Title Cross-Site request forgery (CSRF) vulnerability in Sync Breeze Enterprise Server
First Time appeared Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
Weaknesses CWE-352
CPEs cpe:2.3:a:flexense:disk_pulse_enterprise:v10.4.18:*:*:*:*:*:*:*
cpe:2.3:a:flexense:sync_breeze_enterprise_server:v10.4.18:*:*:*:*:*:*:*
Vendors & Products Flexense
Flexense disk Pulse Enterprise
Flexense sync Breeze Enterprise Server
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published: 2026-01-28T11:52:51.985Z

Updated: 2026-01-28T15:43:40.929Z

Reserved: 2025-09-23T10:22:34.912Z

Link: CVE-2025-59893

cve-icon Vulnrichment

Updated: 2026-01-28T15:43:33.539Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-28T12:15:50.827

Modified: 2026-02-10T21:08:26.120

Link: CVE-2025-59893

cve-icon Redhat

No data.