Red Hat Password_Reset Unvalidated Redirect
CVE-2026-53683 Published on September 2, 2026
Freeipa: idm: idm/freeipa web ui - client-side open redirect in reset_password.html
reset_password.html parses query string parameters and uses the 'url' parameter as a redirection target (window.location = url) after password reset, optionally delayed by a 'delay' parameter. No validation or allowlisting is performed on url, enabling an attacker to redirect users to an arbitrary external site after completion of the password-reset workflow.
Vulnerability Analysis
CVE-2026-53683 can be exploited with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality, with no impact on integrity, and no impact on availability.
Timeline
Reported to Red Hat.
Made public. 81 days later.
Products Associated with CVE-2026-53683
Want to know whenever a new CVE is published for Red Hat Enterprise Linux (RHEL)? stack.watch will email you.