PT-2026-68818 · Pilos · Pilos

CVE-2026-71555

·

Published

2026-08-06

·

Updated

2026-08-07

CVSS v3.1

4.1

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions PILOS versions 2.1.0 through 4.14.0
Description PILOS fails to send a Cross-Origin-Opener-Policy response header. This allows pages opened via links that create a new browsing context, such as those using target=" blank", to maintain a window.opener reference to the original PILOS tab. A malicious destination page can exploit this through reverse tabnabbing—a technique where the attacker uses the window.opener reference to navigate or manipulate the originating tab—potentially redirecting authenticated users to a phishing page that mimics the legitimate interface.
Recommendations Update to version 4.14.1.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71555
GHSA-J4WR-P8GH-XRW5

Affected Products

Pilos