Open redirect in Pivotal Concourse - CVE-2026-49826
Published: August 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to redirect users to an untrusted site.
The vulnerability exists due to open redirect in the login flow redirect_uri handling in skymarshal skyserver when processing a crafted login URL. A remote attacker can send a specially crafted URL to redirect users to an untrusted site.
User interaction is required, and the redirection occurs after the login flow completes.