Open redirect in Pivotal Concourse - CVE-2026-49826

 

Open redirect in Pivotal Concourse - CVE-2026-49826

Published: August 19, 2026


Vulnerability identifier: #VU144315
CSH Severity: Low
CVSS v4: 0 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-49826
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect users to an untrusted site.

The vulnerability exists due to open redirect in the login flow redirect_uri handling in skymarshal skyserver when processing a crafted login URL. A remote attacker can send a specially crafted URL to redirect users to an untrusted site.

User interaction is required, and the redirection occurs after the login flow completes.


Affected software

Pivotal Concourse

How to mitigate CVE-2026-49826

Install security update from vendor's website.

Pivotal Concourse - update to 8.2.3

External References

Related Security Bulletins