CVE-2026-83589

MEDIUM Status: Received

CVSS Scores

CVSS v3.x Base Score
6.1
MEDIUM

Description

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability by enticing a user to follow a specially crafted link, resulting in the user being redirected to an arbitrary external website after authenticating. This open redirect can be leveraged to conduct phishing attacks or credential theft.

Published
October 1, 2026 10:17 AM
Last Modified
October 1, 2026 10:17 AM
Source
[email protected]

Weaknesses (CWE)

CWE-601

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.