CVE-2026-26927 Details
Description
Szafir SDK Web is a browser plug-in that can run SzafirHost application which download the necessary files when launched. In Szafir SDK Web it is possible to change the URL (HTTP Origin) of the application call location. An unauthenticated attacker can craft a website that is able to launch SzafirHost application with arbitrary arguments via Szafir SDK Web browser addon. No validation will be performed to check whether the address specified in `document_base_url` parameter is in any way related to the actual address of the calling web application. The URL address specified in `document_base_url` parameter is then shown in the application confirmation prompt. When a victim confirms the execution of the application, it will be called in the context of attacker's website URL and might download additional files and libraries from that website. When victim accepts the application execution for the URL showed in the confirmation prompt with the "remember" option before, the prompt won't be shown and the application will be called in the context of URL provided by the attacker without any interaction. This issue was fixed in version 0.0.17.4.
A vulnerability exists in the Szafir SDK Web browser plugin, which can launch the SzafirHost application with arbitrary arguments. This issue affects all versions of Szafir SDK Web prior to 0.0.17.4 and all versions of SzafirHost prior to 1.1.0. An unauthenticated attacker can create a website that triggers the SzafirHost application through the Szafir SDK Web addon. The vulnerability arises because there is no validation of the 'document_base_url' parameter, allowing it to be manipulated. When the application is launched, it can download additional files from the attacker's specified URL. If the victim has previously allowed the application to run for that URL with the 'remember' option, the confirmation prompt is bypassed, and the application executes with the attacker's parameters without any user interaction.
Users can update to Szafir SDK Web version 0.0.17.4 or later to address this vulnerability. For SzafirHost, the application should be updated to version 1.1.0 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 2, 2026CISA-ADP
Assessed Apr 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/04/CVE-2026-26927 | [email protected] | AdvisoryBundleRemedy |
| https://www.elektronicznypodpis.pl/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Krajowa Izba Rozliczeniowa Szafir SDK Web | All versions |
CPE
Remediation
| |
| Krajowa Izba Rozliczeniowa SzafirHost | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 2, 2026 | New CVE Received | [email protected] |
Volerion