Information Disclosure in Avira Password Manager for Mozilla Firefox
CVE-2026-12068

7.4HIGH

Key Information:

Vendor
CVE Published:
12 June 2026

What is CVE-2026-12068?

An information disclosure vulnerability exists in Avira Password Manager when integrated with Mozilla Firefox. This flaw allows remote attackers to exploit a cross-origin iframe to access credentials that have been autofilled on the parent web page, due to incorrect field selection during the autofill process. This issue impacts users across various operating systems, including Windows, macOS, and Linux, which makes it critical for users of the affected software to take immediate action to protect their data.

Affected Version(s)

Avira Password Manager Firefox *

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Riccardo, an independent security researcher at TU Wien
.