Security Advisory

CVE-2026-10839

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-06-17 11:11:56
Last updated 2026-06-17 14:57:50
Assigner INCIBE
CVSS score 5.1
State PUBLISHED

Description

Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the application. A successful exploit could redirect authenticated users to malicious sites following login procedures or interaction with the interface, resulting in limited impact on confidentiality and integrity.