SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityReceived

CVE-2026-3096

The product's web portals allow external links to be opened in a new browser tab.

MEDIUM 4.7EPSS 0.21%

Does this matter?

Lower severity and a low EPSS score (0.21%). Track it; it rarely justifies an emergency change on its own.

Description

The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navigating to external destinations. This vulnerability could allow an attacker to manipulate the original trusted application window after a user clicks a malicious external link. This manipulation can lead to users being redirected to phishing pages, enabling credential theft, or facilitating other unauthorized actions within the context of the trusted site.

CVSS 3.1
4.7 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:L/A:N
EPSS
0.21% probability · 11th percentile
CISA KEV
Not listed
Weakness
CWE-20, CWE-603
Source
ed10eef1-636d-4fbe-9993-6890dfa878f8

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.