Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sat, 29 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested_location, and two_factor_auth_return_to_requested_location features. Attackers can craft paths with leading double slashes that browsers resolve as protocol-relative URLs, redirecting authenticated users to attacker-controlled sites after login or password confirmation. | |
| Title | Rodauth before 2.47.0 Open Redirect via Return-to Path | |
| Weaknesses | CWE-601 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-29T16:35:29.723Z
Reserved: 2026-08-29T14:11:07.093Z
Link: CVE-2026-82467
No data.
Status : Received
Published: 2026-08-29T17:17:59.057
Modified: 2026-08-29T17:17:59.057
Link: CVE-2026-82467
No data.
OpenCVE Enrichment
Updated: 2026-08-29T17:30:12Z