CVE 7.4 HIGH

Avira Password Manager credential disclosure via cross-origin autofill in Firefox_CVE-2026-12068

7.4 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N

Description

Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection.

This issue affects Avira Password Manager when used with Mozilla Firefox on Windows, macOS, and Linux.

Basic Information

ID CVE-2026-12068
Source GEN
Published Jun 12, 2026 at 22:19

Affected Product

Vendor Gen Digital
Product Avira Password Manager
Version *
Affected Versions Gen Digital Avira Password Manager *

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.