CVE-2026-101151
MEDIUM
NVD
CVSS Score
4.3
Severity
MEDIUM
Published
Oct 06, 2026
Vendor
unknown
Description
Insufficient validation of request in login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, redirects the user's browser to an arbitrary external site upon completion of the authentication process.