Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the application. A successful exploit could redirect authenticated users to malicious sites following login procedures or interaction with the interface, resulting in limited impact on confidentiality and integrity.
CVSS
No CVSS.
References
Configurations
No configuration.
History
17 Jun 2026, 16:18
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-06-17 13:19
Updated : 2026-06-17 16:18
NVD link : CVE-2026-10839
Mitre link : CVE-2026-10839
CVE.ORG link : CVE-2026-10839
JSON object : View
Products Affected
No product.
CWE
CWE-601
URL Redirection to Untrusted Site ('Open Redirect')
