CVE-2026-101270: HTML injection
Published Sep 29, 2026
·Updated
Malicious HTML content could be injected into the help texts of various fields with organizer permissions.
Event History
Sep 29, 2026
CVE Published
via MITRE·12:02 PM
Data Sourced
via MITRE·12:02 PM
Description
Data Sourced
via NVD·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
The attacker needs organizer permissions to inject malicious HTML into help text for various fields.