PT-2026-61630 · Unknown · Datacycle-Core

CVE-2026-32824

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions dataCycle-CORE versions prior to 26.06.08
Description A low-privileged authenticated API user can provide forwardToUrl and redirectUrl values during password reset or confirmation flows. These values are embedded into the outgoing email workflow without host allowlisting, allowing an attacker to send password reset or confirmation links with tokens attached to an attacker-controlled forwardToUrl, or redirect the browser to an attacker-controlled redirectUrl after a legitimate password reset. This can be exploited for phishing, token capture, confirmation hijacking, or steering victims to an attacker-controlled domain.
Recommendations Update to version 26.06.08.

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-32824

Affected Products

Datacycle-Core