Cross Site Request Forgery vulnerability in diskoverdata diskover-community v.2.3.5. and before allows a remote attacker to escalate privileges and obtain sensitive information via the public/settings_process.php
https://github.com/VadlaReddySai/diskoverdata-cve-writeups/blob/main/CVE-2026-38934