Feed/CVE-2026-48902
CVE-2026-48902CRITICALCVSS 9.8

CVE-2026-48902

Published May 26, 2026·Updated Jul 24, 2026

NVD Description

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free