{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-18721", "assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "state": "PUBLISHED", "assignerShortName": "VulDB", "dateReserved": "2026-08-03T17:42:19.724Z", "datePublished": "2026-08-04T02:30:07.618Z", "dateUpdated": "2026-08-04T14:51:19.648Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "1af790b2-7ee1-4545-860a-a788eba489b5", "shortName": "VulDB", "dateUpdated": "2026-08-04T02:30:07.618Z" }, "title": "kalcaddle kodbox SSO API Login apiLogin redirect", "problemTypes": [ { "descriptions": [ { "type": "CWE", "cweId": "CWE-601", "lang": "en", "description": "Open Redirect" } ] } ], "affected": [ { "vendor": "kalcaddle", "product": "kodbox", "versions": [ { "version": "1.67 Build 02", "status": "affected" } ], "cpes": [ "cpe:2.3:a:kalcaddle:kodbox:*:*:*:*:*:*:*:*" ], "modules": [ "SSO API Login" ] } ], "descriptions": [ { "lang": "en", "value": "A vulnerability has been found in kalcaddle kodbox 1.67 Build 02. This issue affects some unknown processing of the file /user/sso/apiLogin of the component SSO API Login. The manipulation of the argument callbackUrl leads to open redirect. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way." } ], "metrics": [ { "cvssV4_0": { "version": "4.0", "baseScore": 5.3, "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P", "baseSeverity": "MEDIUM" } }, { "cvssV3_1": { "version": "3.1", "baseScore": 4.3, "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM" } }, { "cvssV3_0": { "version": "3.0", "baseScore": 4.3, "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R", "baseSeverity": "MEDIUM" } }, { "cvssV2_0": { "version": "2.0", "baseScore": 5, "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR" } } ], "timeline": [ { "time": "2026-08-03T00:00:00.000Z", "lang": "en", "value": "Advisory disclosed" }, { "time": "2026-08-03T02:00:00.000Z", "lang": "en", "value": "VulDB entry created" }, { "time": "2026-08-03T19:47:30.000Z", "lang": "en", "value": "VulDB entry last update" } ], "credits": [ { "lang": "en", "value": "lihongming (VulDB User)", "type": "reporter" }, { "lang": "en", "value": "VulDB CNA Team", "type": "coordinator" } ], "references": [ { "url": "https://vuldb.com/vuln/385632", "name": "VDB-385632 | kalcaddle kodbox SSO API Login apiLogin redirect", "tags": [ "vdb-entry", "technical-description" ] }, { "url": "https://vuldb.com/vuln/385632/cti", "name": "VDB-385632 | CTI Indicators (IOB, IOC, TTP, IOA)", "tags": [ "signature", "permissions-required" ] }, { "url": "https://vuldb.com/cve/CVE-2026-18721", "name": "CVE-2026-18721 | CVE Analysis and Report", "tags": [ "third-party-advisory" ] }, { "url": "https://vuldb.com/submit/856181", "name": "Submit #856181 | kalcaddle / kodcloud kodbox 1.67 build 02 Open Redirect", "tags": [ "third-party-advisory" ] }, { "url": "https://github.com/sjmycz/cve/issues/6", "tags": [ "exploit", "issue-tracking" ] } ], "x_generator": [ "VulDB PVTS v202608" ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-08-04T14:48:48.867503Z", "id": "CVE-2026-18721", "options": [ { "Exploitation": "poc" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-08-04T14:51:19.648Z" } } ] } }