Junglewise Threat Intelligence

CVE-2026-12068: Avira Password Manager information disclosure in Mozilla Firefox

CVE-2026-12068 · Severity: high · CVSS 7.4 · Published 2026-06-12

Technologies: Avira Password Manager. Vendors: Avira.

Executive brief

Avira Password Manager is a tool used to securely store and automatically fill login credentials for websites. A security flaw when using the software with the Mozilla Firefox browser could allow a malicious website to trick the manager into filling a user's sensitive credentials into a hidden, unauthorized part of the page. This could lead to the theft of usernames and passwords without the user's knowledge.

Technical details

An information disclosure vulnerability exists in the Avira Password Manager extension when used with Mozilla Firefox. The root cause is incorrect autofill field selection logic, which fails to properly isolate parent page fields from cross-origin iframes. A remote attacker can host a malicious page that embeds a target site within an iframe; if the user has credentials saved for the parent site, the extension may incorrectly autofill those credentials into fields controlled by the attacker's iframe. This bypasses the Same-Origin Policy (SOP) for credential handling, allowing for the silent extraction of sensitive login data. The vulnerability affects users on Windows, macOS, and Linux.

Affected products

  • Avira Password Manager All versions used with Mozilla Firefox on Windows, macOS, and Linux

Timeline

  • 2026-06-12: disclosed: Initial publication of CVE-2026-12068
  • 2026-06-12: advisory

References