CVE-2026-82811: Toggl OÜ Toggl Track Extension postMessage origin validation
A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of attacker access is required to exploit this issue?
The vulnerability can be initiated remotely and requires no privileges. User interaction is required, according to the supplied vector.
What is known about affected versions?
The provided information identifies Toggl Track Extension version 4.11.16. It does not establish whether earlier or later versions are affected.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.
What security impact is indicated?
The supplied severity vector indicates low integrity and availability impact, with no confidentiality impact. The issue is rated medium severity with a 5.4 score.