CVE-2026-13202: HTML Injection in OTDS Swagger UI
Published Aug 17, 2026
·Updated
A vulnerability in OpenText Opentext Directory Services allows Input Data Manipulation.
This issue affects Opentext Directory Services: through 22.2.
Affected Software
1 affected component
OpenText OpenText Directory Services<=22.2
Event History
Aug 17, 2026
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-13202?
CVE-2026-13202 has a risk score of 31, indicating a medium level of severity.
2
What software is affected by CVE-2026-13202?
CVE-2026-13202 affects OpenText Directory Services up to version 22.2.
3
What type of vulnerability is CVE-2026-13202 classified as?
CVE-2026-13202 is classified as an HTML Injection vulnerability, specifically linked to Cross-Site Scripting (XSS).
4
How do I fix CVE-2026-13202?
To fix CVE-2026-13202, ensure that you update OpenText Directory Services to the latest version beyond 22.2.
5
Can CVE-2026-13202 lead to unauthorized data manipulation?
Yes, CVE-2026-13202 allows for input data manipulation, which can lead to unauthorized access and potential data breaches.