๐Ÿ” CVE Alert

CVE-2026-49826

UNKNOWN 0.0

Concourse login flow has an open redirect issue

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Concourse is a container-based automation system written in Go. Prior to version 8.2.3, an attacker is able to craft and send a user a URL that will redirect the user from the Concourse web server to any other site. This could be used in a phishing attack to steal user's credentials. This has been fixed in 8.2.3. No known workarounds are available.

CWE CWE-601
Vendor concourse
Product concourse
Published Aug 14, 2026
Last Updated Aug 14, 2026
Stay Ahead of the Next One

Get instant alerts for concourse concourse

Be the first to know when new unknown vulnerabilities affecting concourse concourse are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

concourse / concourse
< 8.2.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/concourse/concourse/security/advisories/GHSA-8w27-c4vc-88q9 github.com: https://github.com/concourse/concourse/commit/ac60be5f0435b6592f5a4fcc089050d72ad2452c github.com: https://github.com/concourse/concourse/releases/tag/v8.2.3