ImportantSecurity & Privacy
CVE-2026-101152: Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a... (CVSS 8)
Insufficient validation in the Single Sign-On (SSO) login flow could allow a remote, unauthenticated attacker to craft a URL that, when clicked by a user, causes the identity provider (IdP) to deliver authentication material to an attacker-controlled URL instead of to CloudVision.
Vulners1 min read
