PT-2026-61630 · Unknown · Datacycle-Core
CVE-2026-32824
·
Published
2026-07-20
·
Updated
2026-07-20
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
dataCycle-CORE versions prior to 26.06.08
Description
A low-privileged authenticated API user can provide
forwardToUrl and redirectUrl values during password reset or confirmation flows. These values are embedded into the outgoing email workflow without host allowlisting, allowing an attacker to send password reset or confirmation links with tokens attached to an attacker-controlled forwardToUrl, or redirect the browser to an attacker-controlled redirectUrl after a legitimate password reset. This can be exploited for phishing, token capture, confirmation hijacking, or steering victims to an attacker-controlled domain.Recommendations
Update to version 26.06.08.
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Datacycle-Core