SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-14171

MEDIUM · CVSS 6.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The vulnerability allows unauthenticated remote attackers to exploit improper validation in the post-login redirect of a web user interface, potentially redirecting users to malicious websites. This could lead to loss of confidentiality and availability of sensitive information. Organizations utilizing affected web applications should prioritize remediation to protect users from phishing attacks and data compromise.

CVE
CVE-2026-14171
Severity
MEDIUM
CVSS
6.1
EPSS
0.23%

Original NVD Description

An unauthenticated remote attacker can abuse the improper validation of the post-login redirect of the web-UI to trick users to a malicious website. This can result in a loss of confidentiality and availability.