Impact
The vulnerability is an open redirect in Ivanti Xtraction before version 2026.2.1, allowing a remote unauthenticated attacker to redirect users to arbitrary external URLs. The weakness is classified as CWE‑601. This flaw can be triggered by simply visiting a maliciously crafted URL, so the attack vector is remote and unauthenticated.
Affected Systems
This vulnerability impacts the Ivanti Xtraction product, affecting all releases before version 2026.2.1. No further sub‑versions are specified, so any installation older than 2026.2.1 is considered vulnerable.
Risk and Exploitability
The CVSS score of 4.0 indicates a moderate severity level. The EPSS score is below 1%, reflecting a low probability of exploitation in the wild, and the issue is not listed in the CISA KEV catalog. The flaw can be triggered simply by any user visiting a maliciously crafted URL, so the attack vector is remote and unauthenticated. The risk is moderate but present if redirect traffic is not otherwise controlled.
OpenCVE Enrichment