CVE-2026-12068
Severity CVSS v4.0:
Pending analysis
Type:
CWE-669
Incorrect Resource Transfer Between Spheres
Publication date:
12/06/2026
Last modified:
12/06/2026
Description
Information disclosure vulnerability in Avira Password Manager when used with Mozilla Firefox may allow a remote attacker operating a cross-origin iframe to obtain credentials autofilled for the parent web page via incorrect autofill field selection.<br />
<br />
This issue affects Avira Password Manager when used with Mozilla Firefox on Windows, macOS, and Linux.
Impact
Base Score 3.x
7.40
Severity 3.x
HIGH



