CVE-2026-0397 - Information disclosure via CORS misconfiguration
CVE ID :CVE-2026-0397
Published : March 31, 2026, 12:16 p.m. | 49 minutes ago
Description :When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin Resource Sharing (CORS) policy.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : March 31, 2026, 12:16 p.m. | 49 minutes ago
Description :When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin Resource Sharing (CORS) policy.
Severity: 3.1 | LOW
Visit the link for more details, such as CVSS details, affected products, timeline, and more...