Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-53683— Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

会解析查询字符串参数,并在密码重置完成后将 参数作为重定向目标( ),同时可通过 参数可选地设置延迟重定向。由于对 未进行任何验证或白名单过滤,攻击者可借此将用户重定向到任意外部网站。

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-53683

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html
Source: CVE Program / CVE List V5
Vulnerability Description
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9

II. Public POCs for CVE-2026-53683

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-53683

登录查看更多情报信息。

Vendor Advisories for CVE-2026-53683 (1)

Other References for CVE-2026-53683 (1)

Same Patch Batch · Red Hat · 2026-09-02 · 7 CVEs total

CVE-2026-78408 7.9 HIGH Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
CVE-2026-84838 7.8 HIGH Rpm: command injection in rpmuncompress via unescaped filenames passed to popen()
CVE-2026-84837 7.8 HIGH Rpm: command injection in `rpmbuild -t*` (`gettarspec`) via unescaped tarball path
CVE-2026-78410 7.8 HIGH Util-linux: util-linux: restricted bind mounts do not pin the source, allowing x-mount.own
CVE-2026-78409 7.0 HIGH Util-linux: util-linux: x-mount.subdir detached-tree resolution can escape via intermediat
CVE-2026-82968 6.4 MEDIUM Keycloak-services: keycloak-services: cross-session email verification proof not bound to

IV. Related Vulnerabilities

V. Comments for CVE-2026-53683

No comments yet


Leave a comment