CWE-603
CVEs classified under CWE-603, newest first.
3 CVEsRSS
CVE-2026-3096Medium· 4.7The product's web portals allow external links to be opened in a new browser tab
The product's web portals allow external links to be opened in a new browser tab. In certain configurations, the originating window retains access to the newly opened page, allowing interaction between the two browser contexts when navig…
▾ SunlitWSO2 · WSO2 API Control PlaneEPSS 0.21%via NVD
CVE-2026-66305High· 7.1Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
Use of client-side authentication in Skype for Business allows an authorized attacker to perform spoofing over a network.
▾ Twilightmicrosoft · skype_for_business_serverEPSS 0.30%via NVD
CVE-2026-8830Medium· 4.3A flaw was found in Keycloak
A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side processAction() fails to validate that…
▾ SunlitEPSS 0.39%via NVD