PT-2026-50379 · Password Manager · Passwords Manager

CVE-2026-10839

·

Published

2026-06-17

·

Updated

2026-06-17

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions The product name cannot be determined (affected versions not specified)
Description An open redirection issue in the authentication system allows an attacker to manipulate the X-Forwarded-Host header to alter URLs generated by the application. This can lead to authenticated users being redirected to malicious websites after completing login procedures or interacting with the interface, which may impact confidentiality and integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10839

Affected Products

Passwords Manager