NONE · 0

CVE-2026-76203

Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from oth...

Vulnerability Description

Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from other users' browsers, disclosing their IP address and User-Agent, via CSS hex escapes that reconstruct the url() function and evade the sanitizer blocklist

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-76203?

CVE-2026-76203 is a documented vulnerability. Incorrect Behavior Order: Validate Before Canonicalize in the report theme CSS sanitizer in maalfer Pentestify 1.2.0 through 2.3.2 allows an authenticated user to force outbound HTTP requests from oth...

How severe is CVE-2026-76203?

CVSS scoring is not yet available for CVE-2026-76203. Check NVD for updates.

Is there a patch for CVE-2026-76203?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.