CVE-2026-27508: Smoothwall Express < 3.1 Update 13 Reflected XSS in redirect.cgi via url Parameter
Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can craft malicious URLs with javascript: schemes that execute arbitrary JavaScript in victims' browsers when clicked through the unsanitized link.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Smoothwall Expressto a version that resolves this vulnerability.Fixed in 3.1 Update 13
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27508?
CVE-2026-27508 is classified as a medium severity vulnerability due to its potential for reflected cross-site scripting attacks.
How do I fix CVE-2026-27508?
To fix CVE-2026-27508, update Smoothwall Express to version 3.1 Update 13 or later.
What systems are affected by CVE-2026-27508?
CVE-2026-27508 affects Smoothwall Express versions prior to 3.1 Update 13.
What type of vulnerability is CVE-2026-27508?
CVE-2026-27508 is a reflected cross-site scripting (XSS) vulnerability.
What can attackers do with CVE-2026-27508?
Attackers can exploit CVE-2026-27508 to execute malicious scripts in the context of a user’s session.