CVE-2026-101152: Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a... (CVSS 8)

Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.

Vulners1 min read
Read full article
CVE-2026-101152: Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a... (CVSS 8)

Read the full story at Vulners →