CVE-2026-101151: Security Advisory 0187
Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user's browser to an arbitrary external site upon completion of the authentication process.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2025.3.4 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.1.3 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.2.1
Event History
Frequently Asked Questions
What user interaction is required for exploitation?
An attacker must craft a URL and persuade a user to click it. The redirect occurs after the user completes the authentication process.
What is the likely impact of a successful exploit?
The user's browser can be redirected to an arbitrary external site. The provided data indicates limited confidentiality impact and no integrity or availability impact.
Does an attacker need an account or prior authentication?
No. The attacker is remote and unauthenticated, and no privileges are required to craft the malicious URL.