🔐 CVE Alert

CVE-2026-82811

MEDIUM 5.4

Toggl OÜ Toggl Track Extension postMessage origin validation

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

A security vulnerability has been detected in Toggl OÜ Toggl Track Extension 4.11.16. This affects an unknown function of the component postMessage Handler. The manipulation leads to origin validation error. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

CWE CWE-346 CWE-345
Vendor toggl oü
Product toggl track extension
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for toggl oü toggl track extension

Be the first to know when new medium vulnerabilities affecting toggl oü toggl track extension are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Toggl OÜ / Toggl Track Extension
4.11.16

References

NVD ↗ CVE.org ↗ EPSS Data ↗
vuldb.com: https://vuldb.com/vuln/397230 vuldb.com: https://vuldb.com/vuln/397230/cti vuldb.com: https://vuldb.com/cve/CVE-2026-82811 vuldb.com: https://vuldb.com/submit/875273 github.com: https://github.com/xryj920/chrome_extensions/blob/main/Toggl%20O%C3%9C%20Toggl%20Track%204.11.16%20accepts%20forged%20session-state%20messages%20through%20an%20unauthenticated%20postMessage%20handler

Credits

🔍 DRXYJ (VulDB User) VulDB CNA Team