Frequency
1
occurrences
First Seen
August 22, 2026
Last Seen
August 22, 2026
Related Threat Clusters
-
CVE-2026-49996: SecureDrop Client Vulnerability Allows Cross-Origin Redirects
A vulnerability identified as CVE-2026-49996 affects the SecureDrop Client, a desktop application used by journalists for secure communication. Prior to version 1.3.1, a malicious SecureDrop Server could exploit this…
3 articles · Updated August 22, 2026
Recent Intelligence Reports
- CVE-2026-49996: securedrop-proxy origin limitation can be bypassed with redirects [LOW] CVSS 3.7 Exploit Intelligence - Recent CVEs / 1d SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has multiple layers of built-in hardening, and is — exploit-intel.com · August 22, 2026