CVE-2026-10839
Received
Received - Intake
Open Redirection in Authentication System via X-Forwarded-Host Header
Publication date: 2026-06-17
Last updated on: 2026-06-17
Assigner: Spanish National Cybersecurity Institute, S.A. (INCIBE)
Description
Description
Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the application. A successful exploit could redirect authenticated users to malicious sites following login procedures or interaction with the interface, resulting in limited impact on confidentiality and integrity.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
Currently, no data is known.
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-601 | The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect. |