URL Redirection Issue in Concourse Automation System by Concourse
CVE-2026-49826

NONE

Key Information:

Vendor

Concourse

Status
Vendor
CVE Published:
14 August 2026

What is CVE-2026-49826?

Concourse, a container-based automation system, has a vulnerability that allows an attacker to craft a malicious URL, redirecting unsuspecting users from the Concourse web server to any external website. This flaw can be exploited in phishing attacks, potentially compromising users' credentials. The issue has been resolved in version 8.2.3 of Concourse. Users are advised to upgrade as no known workarounds are available.

Affected Version(s)

concourse < 8.2.3

References

CVSS V4

Score:
Severity:
NONE
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.