CVE-2026-10839: Password Manager

Medium severity, CVSS 5.1. EPSS: 0.4% chance of exploitation in the next 30 days.

Open redirection vulnerability in the authentication system allows an attacker to use manipulated values in the X-Forwarded-Host header to alter the URLs generated by the application. A successful exploit could redirect authenticated users to malicious sites following login procedures or interaction with the interface, resulting in limited impact on confidentiality and integrity.

Affected products

Published 2026-06-17. Last modified 2026-06-17.