CVE-2026-26927
Last modified
CVE-2026-26927 is a medium-severity vulnerability rated 5.1/10 on the CVSS scale. Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched. In Szafir SDK Web it is possible to change the URL (HTTP Origin) of the application call location. An unauthenticated attacker can craft a website that is able to launch SzafirHost application with arbitrary arguments via Szafir SDK Web browser addon. No validation will be performed to check whether the address specified in `document_base_url` parameter is in any way related to the actual address of the calling web application. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched. In Szafir SDK Web it is possible to change the URL (HTTP Origin) of the application call location. An unauthenticated attacker can craft a website that is able to launch SzafirHost application with arbitrary arguments via Szafir SDK Web browser addon. No validation will be performed to check whether the address specified in `document_base_url` parameter is in any way related to the actual address of the calling web application. The URL address specified in `document_base_url` parameter is then shown in the application confirmation prompt. When a victim confirms the execution of the application, it will be called in the context of attacker's website URL and might download additional files and libraries from that website. When victim accepts the application execution for the URL showed in the confirmation prompt with the "remember" option before, the prompt won't be shown and the application will be called in the context of URL provided by the attacker without any interaction. This issue was fixed in version 0.0.17.4.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-26927?
How severe is CVE-2026-26927?
How do I fix CVE-2026-26927?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-26891Sourcecodester Logistic Hub Parcel's Management System v1.0 …2.7
- CVE-2026-26892Sourcecodester Logistic Hub Parcel's Management System v1.0 …7.2
- CVE-2026-26895User enumeration vulnerability in /pwreset.php in osTicket v…5.3
- CVE-2026-2690A flaw has been found in itsourcecode Event Management Syste…9.8
- CVE-2026-2691A vulnerability has been found in itsourcecode Event Managem…9.8
- CVE-2026-2692A vulnerability was found in CoCoTeaNet CyreneAdmin up to 1.…6.5
- CVE-2026-26928SzafirHost downloads necessary files in the context of the i…8.7
- CVE-2026-26929Apache Airflow versions 3.0.0 through 3.1.7 FastAPI DagVersi…6.5
- CVE-2026-2693A vulnerability was determined in CoCoTeaNet CyreneAdmin up …6.5
- CVE-2026-26930SmarterTools SmarterMail before 9526 allows XSS via MAPI req…7.2
- CVE-2026-26931Memory Allocation with Excessive Size Value (CWE-789) in the…5.7
- CVE-2026-26932Improper Validation of Array Index (CWE-129) in the PostgreS…7.5
Are you affected by CVE-2026-26927?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
