CVE-2026-101157: Security Advisory 0192
A stored cross-site scripting (XSS) vulnerability may allow an unauthenticated attacker with adjacent-network access to inject malicious content that executes when an authenticated user views affected content. Successful exploitation may allow the attacker to compromise the victim's authenticated browser session, access sensitive data, modify system state, or disrupt affected services.
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2026.2.1Patch Security Advisory 0192
Event History
Frequently Asked Questions
Does an attacker need an account or Internet-level access to exploit this issue?
No attacker authentication is required, but the attacker must have adjacent-network access. Exploitation also depends on an authenticated user viewing the injected affected content.
What could an attacker gain if the exploit succeeds?
The attacker may compromise the authenticated victim's browser session, access sensitive data, modify system state, or disrupt affected services.