CVE-2026-101152
EUVD-2026-9394806.10.2026, 20:17
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
Awaiting analysis
This vulnerability is currently awaiting analysis.
Common Weakness Enumeration