CVE-2026-66773 - Server-controlled `__next` URL is not checking cross-origin
CVE ID :CVE-2026-66773
Published : Aug. 11, 2026, 12:18 a.m. | 1 hour, 9 minutes ago
Description :A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact on confidentiality and low impact on integrity and no impact on Availability.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Aug. 11, 2026, 12:18 a.m. | 1 hour, 9 minutes ago
Description :A malicious or compromised OData service could disclose sensitive authentication information and inject untrusted data into the application, which may leads to a high impact on confidentiality and low impact on integrity and no impact on Availability.
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...