AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-19078

MEDIUM · CVSS 4.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

An open redirect vulnerability in the oauth-server component allows remote attackers to exploit the improperly validated 'then' parameter in the grant approval handler. This could lead to phishing attacks, where users are redirected to malicious sites, potentially compromising sensitive information. Organizations utilizing this component should prioritize remediation to protect their users from such threats.

CVE
CVE-2026-19078
Severity
MEDIUM
CVSS
4.3
EPSS
0.26%

Original NVD Description

A flaw was found in the oauth-server component. This open redirect vulnerability occurs when the 'then' parameter in the grant approval handler is not properly validated. A remote attacker can craft a malicious URL that, when approved or denied by an authenticated user, redirects them to an attacker-controlled website. This could enable phishing attacks, potentially tricking users into revealing sensitive information.