CVE-2026-1406 Details
Description
A vulnerability was determined in lcg0124 BootDo up to 5ccd963c74058036b466e038cff37de4056c1600. Affected by this vulnerability is the function redirectToLogin of the file AccessControlFilter.java of the component Host Header Handler. This manipulation of the argument Hostname causes open redirect. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available.
A host header injection vulnerability has been identified in lcg0124 BootDo versions prior to 5ccd963c74058036b466e038cff37de4056c1600. The issue resides in the AccessControlFilter.java file, specifically within the redirectToLogin function. This vulnerability allows for open redirects by manipulating the Host header, which can be exploited remotely. The vulnerability has been publicly disclosed and is available as a proof-of-concept exploit.
It is recommended to reject unknown or mismatched Host headers, use secure absolute URLs for redirects and password reset links, and enable reverse-proxy validation to overwrite the Host header with the correct internal value before the request reaches the backend.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 25, 2026CISA-ADP
Assessed Jan 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/webzzaa/CVE-/issues/5 | [email protected] | ExploitIssue TrackingRemedy |
| https://vuldb.com/?ctiid.342794 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/?id.342794 | [email protected] | AdvisoryExploitTechnical Description |
| https://vuldb.com/?submit.736271 | [email protected] | ExploitTechnical Description |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lcg0124 BootDo | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 29, 2026 | Data Remediation | [email protected] |
| Jan 25, 2026 | New CVE Received | [email protected] |
Volerion