CVE-2026-59788: Stored XSS vulnerability in OAuth configuration form
The email media type OAuth form passes the Authorization endpoint value to window.open() without validating the URL scheme, so a javascript: URL is executed in the browser. This means a crafted media type configuration, deliverable as an import file, runs arbitrary JavaScript as the Super Admin who grants consent.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Super Admin users are exposed when they grant OAuth consent for a crafted email media type configuration. The malicious configuration can be delivered through an import file.
What does an attacker need to exploit it?
An attacker needs to cause a crafted media type configuration containing a javascript: value in the Authorization endpoint field to be imported and then have a Super Admin grant consent.
What is the impact if exploitation succeeds?
The crafted Authorization endpoint is passed to window.open() without URL-scheme validation, causing arbitrary JavaScript to execute in the Super Admin's browser.