PT-2026-83447 · Rodauth · Rodauth

·

CVE-2026-82467

·

Published

2026-08-29

·

Updated

2026-08-31

CVSS v4.0

4.9

Medium

VectorAV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Rodauth versions prior to 2.47.0
Description Insufficient validation of protocol-relative return-to paths occurs within the confirm password, login return to requested location, and two factor auth return to requested location features. This allows attackers to use paths starting with double slashes, which browsers interpret as protocol-relative URLs, to redirect authenticated users to external malicious sites following password confirmation or login.
Recommendations Update to version 2.47.0 or later.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82467
GHSA-H9M4-VM9W-H43M

Affected Products

Rodauth