Skip to content
Qt Group PlcCVE-2026-12379

Qt Group Plc Axivion: open redirect

Medium6.8CVE-2026-12379 · Published Jul 16, 2026

An Open Redirect vulnerability (CWE-601) exists in the OAuth/OIDC authentication implementation of the Axivion Dashboard. The login flow did not properly restrict the post-authentication redirect to the application's own origin, so a user who follows a crafted login link can be sent to an untrusted external site after authenticating against the genuine Dashboard. Because the link points at the legitimate Dashboard, this can be abused for phishing, for example credential or second-factor theft via a convincing look-alike page. Exploitation requires the victim to follow the attacker-supplied link and complete the authentication flow.

Qt Group Plc advisory

Affected versions

PackageAffectedFixed in
Axivion
Product
>= 7.8.0, <= 7.8.12No fix yet
>= 7.9.0, <= 7.9.12No fix yet
>= 7.10.0, <= 7.10.10No fix yet
>= 7.11.0, <= 7.11.6No fix yet
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:M/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-601

More Qt Group Plc advisories

All Qt Group Plc
Advisory
qt: denial of service
High7.1Sep 16
qt: out-of-bounds read
Medium6.9Sep 11
qt: denial of service
High7.1Sep 8
Improper output neutralization
Low2.9Jul 23
Qt: out-of-bounds read
Medium6.3Jul 21
Qt Group Plc Axivion: missing authorization
High8.7Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.