PT-2026-66495 · Dromara+1 · Maxkey

·

CVE-2026-67345

·

Published

2026-07-30

·

Updated

2026-07-30

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MaxKey versions prior to 4.1.13
Description Insufficient redirect URI validation in the hostMatches() function of DefaultRedirectResolver allows remote attackers to hijack OAuth 2.0 authorization codes. By providing a crafted redirect uri where the hostname suffix matches a registered URI without proper dot-boundary anchoring, an attacker controlling a domain that ends with the registered hostname can trick victims into clicking a malicious authorization URL. This results in the authorization code being sent to the attacker-controlled URI and subsequently exchanged for an access token to gain access to the victim's identity.
Recommendations Update MaxKey to version 4.1.13 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67345

Affected Products

Maxkey