First published: Fri Mar 21 2025(Updated: )
** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Oozie. This issue affects Apache Oozie: all versions. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
Credit: security@apache.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apache Oozie | <= |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-26796 is classified as a Cross-site Scripting (XSS) vulnerability with high severity due to its potential impact.
There is no fix available for CVE-2025-26796 as Apache Oozie is no longer supported and maintained.
CVE-2025-26796 affects all versions of Apache Oozie.
CVE-2025-26796 poses the risk of allowing attackers to execute malicious scripts in the context of a user's session.
As this vulnerability is in an unsupported product, there are no official workarounds available for CVE-2025-26796.