Description
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
Published: 2026-07-14
Score: 4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an open redirect in Ivanti Xtraction before version 2026.2.1, allowing a remote unauthenticated attacker to redirect users to arbitrary external URLs. The weakness is classified as CWE‑601. This flaw can be triggered by simply visiting a maliciously crafted URL, so the attack vector is remote and unauthenticated.

Affected Systems

This vulnerability impacts the Ivanti Xtraction product, affecting all releases before version 2026.2.1. No further sub‑versions are specified, so any installation older than 2026.2.1 is considered vulnerable.

Risk and Exploitability

The CVSS score of 4.0 indicates a moderate severity level. The EPSS score is below 1%, reflecting a low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. The flaw can be triggered simply by any user visiting a maliciously crafted URL, so the attack vector is remote and unauthenticated. The risk is moderate but present if redirect traffic is not otherwise controlled.

Generated by OpenCVE AI on July 31, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑provided patch for Ivanti Xtraction version 2026.2.1 or later.
  • Restrict redirect destinations by validating URLs and allowing only trusted internal or approved external addresses.
  • Implement a web‑application firewall rule that detects and blocks suspicious redirect attempts before they reach the application.

Generated by OpenCVE AI on July 31, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Ivanti Xtraction Open Redirect Vulnerability

Sat, 25 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Ivanti Xtraction Open Redirect Vulnerability

Wed, 22 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Open Redirect Vulnerability in Ivanti Xtraction Prior to 2026.2.1

Thu, 16 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Open Redirect Vulnerability in Ivanti Xtraction Prior to 2026.2.1

Thu, 16 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Ivanti
Ivanti xtraction
Vendors & Products Ivanti
Ivanti xtraction

Tue, 14 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Description An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:N'}


Subscriptions

Ivanti Xtraction
cve-icon MITRE

Status: PUBLISHED

Assigner: ivanti

Published:

Updated: 2026-07-14T14:49:48.989Z

Reserved: 2026-07-06T21:20:44.490Z

Link: CVE-2026-14902

cve-icon Vulnrichment

Updated: 2026-07-14T14:49:38.317Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:30:17Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')