CVE-2026-1243: IBM Content Navigator is affected by , a Cross-Site Scripting (XSS) vulnerability
Published Mar 30, 2026
·Updated
IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.
Affected Software
9 affected components
IBM Content Navigator<=3.0.15
IBM Content Navigator<=3.1.0
IBM Content Navigator<=3.2.0
All of the following
Any of the following
IBM Content Navigator=3.0.15
IBM Content Navigator=3.1.0
IBM Content Navigator=3.2.0
Any of the following
IBM AIX
Linux Linux kernel
Microsoft Windows
Remediation
Information
Affected VersionsFixes3.0.15ICN 3.0.15 IF0093.1.0ICN 3.1.0 IF008 LA23.2.0ICN 3.2.0 IF004
Event History
Mar 30, 2026
CVE Published
via IBM·12:00 AM
Data Sourced
via IBM·12:00 AM
Affected Software
Apr 2, 2026
CVE Published
via MITRE·12:14 AM
Data Sourced
via MITRE·12:14 AM
RemedyDescriptionSeverity
Data Sourced
via NVD·01:16 AM
DescriptionSeverityWeaknessAffected Software