CVE-2026-12068

Severity CVSS v4.0:
Pending analysis
Type:
CWE-669 Incorrect Resource Transfer Between Spheres
Publication date:
12/06/2026
Last modified:
12/06/2026

Description

Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection.<br /> <br /> This issue affects Avira Password Manager when used with Mozilla Firefox on Windows, macOS, and Linux.

References to Advisories, Solutions, and Tools