PT-2026-96089 · Host Engineering · Idirect Evolution+1

·

CVE-2026-94214

·

Published

2026-09-21

·

Updated

2026-09-24

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions ST Engineering iDirect Evolution versions prior to 20260717 Velocity WebServer Evolution versions prior to 20260717
Description An open redirect issue exists in the Management Service component within the /login.html file. A remote attacker can trigger this by manipulating the Host argument, which allows the redirection of users to an external site.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-94214

Affected Products

Velocity Webserver Evolution
Idirect Evolution