Junglewise Threat Intelligence

CVE-2026-5754: Radware Alteon reflected XSS in ReturnTo parameter

CVE-2026-5754 · Severity: medium · CVSS 6.1 · Published 2026-04-14

Executive brief

Radware Alteon is a load balancer used to manage and secure web traffic for enterprise applications. A security flaw in its login process allows attackers to trick users into clicking a malicious link that executes unauthorized code in their web browser. This could lead to the theft of login sessions, sensitive data exposure, or unauthorized actions performed on behalf of the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the 'ReturnTo' parameter of the '/protected/login' route in Radware Alteon version 34.5.4.0. The flaw occurs because the load balancer fails to sanitize user input when redirecting users to a Microsoft SAML login page. An unauthenticated remote attacker can exploit this by crafting a malicious URL containing a JavaScript payload in the ReturnTo parameter. If a victim clicks the link, the payload is reflected and executed in their browser context, potentially allowing for session cookie theft or unauthorized API actions. The vendor has indicated a fix is planned for version 34.5.7.0.

Affected products

  • Radware Alteon vADC 34.5.4.0

Timeline

  • 2026-02-09: other: Vendor notified
  • 2026-04-14: disclosed: Initial CVE publication
  • 2026-04-21: advisory: CERT/CC vulnerability note published

References