PT-2026-66495 · Dromara+1 · Maxkey
CVSS v4.0
8.5
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MaxKey versions prior to 4.1.13
Description
Insufficient redirect URI validation in the
hostMatches() function of DefaultRedirectResolver allows remote attackers to hijack OAuth 2.0 authorization codes. By providing a crafted redirect uri where the hostname suffix matches a registered URI without proper dot-boundary anchoring, an attacker controlling a domain that ends with the registered hostname can trick victims into clicking a malicious authorization URL. This results in the authorization code being sent to the attacker-controlled URI and subsequently exchanged for an access token to gain access to the victim's identity.Recommendations
Update MaxKey to version 4.1.13 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maxkey