Junglewise Threat Intelligence

CVE-2026-10837: Password Manager open redirection via X-Forwarded-Host header

CVE-2026-10837 · Severity: info · CVSS 5.1 · Published 2026-06-17

Technologies: Password Manager (eusonlito) Password Manager.

Executive brief

Password Manager, an application used to store and manage credentials for various services, is vulnerable to an open redirection flaw. An attacker can send a specially crafted link to a user that appears to be legitimate but redirects them to a malicious website. This can be used in phishing campaigns to trick users into providing sensitive information or downloading malware.

Technical details

An open redirection vulnerability (CWE-601) exists in Password Manager due to improper validation of the X-Forwarded-Host HTTP header. By manipulating this header, an attacker can craft links that cause the application to redirect users to an arbitrary external domain. This attack requires network reachability and user interaction (clicking a malicious link). The vulnerability was fixed in the update released on August 7, 2025.

Affected products

  • Password Manager (eusonlito) Password Manager versions prior to 2025-08-07

Timeline

  • 2025-08-07: patched: Vulnerability fixed by the Password Manager team.
  • 2026-05-06: advisory: Initial advisory published by INCIBE.
  • 2026-06-17: disclosed: CVE published in NVD.

References