CVE-2026-81691: Unvalidated Server Url Credential Transmissioncve-2026-81691-unvalidated-server-url-credential-transmission
Sensitive credentials or authentication requests are transmitted to a caller-supplied server URL without validating that HTTPS is enforced and the target host is on an allowlist of configured servers.