Junglewise Threat Intelligence

CVE-2026-94216: ST Engineering iDirect Evolution open redirect in HTTP Header Handler

CVE-2026-94216 · Severity: medium · CVSS 4.3 · Published 2026-09-21

Executive brief

ST Engineering iDirect Evolution and Velocity WebServer Evolution contain an open redirect vulnerability in their web server's HTTP header handling logic. An attacker can manipulate the Success argument to redirect users to arbitrary external sites, potentially facilitating phishing attacks or credential theft. The vulnerability is remotely exploitable and has been publicly disclosed with working proof-of-concept code.

Technical details

The vulnerability exists in the authorize function of the /usr/sbin/webserver HTTP Header Handler component, where the Success argument is not properly validated. An attacker can inject crafted HTTP headers to redirect authenticated users to attacker-controlled destinations. The attack requires network access and no special privileges, and has been independently disclosed with public exploit details.

Affected products

  • ST Engineering iDirect Evolution up to 20260717
  • ST Engineering Velocity WebServer Evolution up to 20260717

Timeline

  • 2026-09-21: disclosed: Publicly disclosed with proof-of-concept code
  • 2026-09-21: advisory: CVE-2026-94216 assigned

References

Related threats