CVE-2026-82287: Cors Untrusted Origin With Credentialscve-2026-82287-cors-untrusted-origin-with-credentials
CORS is configured to unconditionally allow any origin while enabling credentials. Reflecting arbitrary request origins with 'credentials: true' allows attackers on third-party sites to execute credentialed cross-origin requests and access sensitive user data.