CVE-2026-0397 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malici…
Low CVSS: 3.1

CVE-2026-0397

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin Resource Sharing (CORS) policy.
Vendor
-
Product
-
CWE
CWE-942
Yayın Tarihi
2026-03-31 12:16:27
Güncelleme
2026-04-01 14:24:02
Source Identifier
security@open-xchange.com
KEV Date Added
-

Kategoriler

Referanslar