CVE-2026-82811
Toggl OÜ Toggl Track Extension postMessage origin validation
CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th
A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
| CWE | CWE-346 CWE-345 |
| Vendor | toggl oü |
| Product | toggl track extension |
| Published | Aug 31, 2026 |
Stay Ahead of the Next One
Get instant alerts for toggl oü toggl track extension
Be the first to know when new medium vulnerabilities affecting toggl oü toggl track extension are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
Toggl OÜ / Toggl Track Extension
4.11.16
References
vuldb.com: https://vuldb.com/vuln/397230 vuldb.com: https://vuldb.com/vuln/397230/cti vuldb.com: https://vuldb.com/cve/CVE-2026-82811 vuldb.com: https://vuldb.com/submit/875273 github.com: https://github.com/xryj920/chrome_extensions/blob/main/Toggl%20O%C3%9C%20Toggl%20Track%204.11.16%20accepts%20forged%20session-state%20messages%20through%20an%20unauthenticated%20postMessage%20handler
Credits
🔍 DRXYJ (VulDB User) VulDB CNA Team