From March 18 through July 10, 2026, the authenticated client intake flow accepted an unvalidated return destination and passed it to client-side navigation after intake completion. A crafted link could cause unintended navigation or, for an unsafe URL scheme, script execution in the page context. Tides found no evidence of exploitation, affected accounts, or customer impact.
Published Jul 31, 2026 · Last updated Jul 31, 2026
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:H/SI:H/SA:N