Unknown · Kalcaddle Kodbox · CVE-2026-18721
**Name of the Vulnerable Software and Affected Versions**
kalcaddle kodbox version 1.67 Build 02
**Description**
An issue exists in the SSO API Login component due to improper processing of the '/user/sso/apiLogin' endpoint. A remote attacker can manipulate the `callbackUrl` argument to trigger an open redirect, which occurs when an application redirects a user to an untrusted external site.
**Recommendations**
As a temporary workaround, restrict access to the '/user/sso/apiLogin' endpoint or avoid using the `callbackUrl` parameter until a fix is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.