Improper Authentication in REDAXO - #VU140851
Published: August 4, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication and obtain a backend session for an existing account.
The vulnerability exists due to improper authentication in the temporary login token handling of the structure/history plugin when processing a temporary frontend login request. A remote attacker can bring the secret into a predictable state and forge a temporary login token to bypass authentication and obtain a backend session for an existing account.
Only installations with the structure/history plugin installed and activated are vulnerable, and the issue can affect administrator accounts.