Information Disclosure in Avira Password Manager for Mozilla Firefox
CVE-2026-12068
7.4HIGH
What is CVE-2026-12068?
An information disclosure vulnerability exists in Avira Password Manager when integrated with Mozilla Firefox. This flaw allows remote attackers to exploit a cross-origin iframe to access credentials that have been autofilled on the parent web page, due to incorrect field selection during the autofill process. This issue impacts users across various operating systems, including Windows, macOS, and Linux, which makes it critical for users of the affected software to take immediate action to protect their data.
Affected Version(s)
Avira Password Manager Firefox *
References
CVSS V3.1
Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Riccardo, an independent security researcher at TU Wien
