CVE-2026-14466: Possible XSS in the SNS web administration panel
It’s possible to run a stored XSS in Stormshield’s web administration panel.
To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Stormshield SNSto a version that resolves this vulnerability.Fixed in 4.8.17 - Upgrade
Upgrade
Stormshield SNSto a version that resolves this vulnerability.Fixed in 5.0.7 - Upgrade
Upgrade
Stormshield SNSto a version that resolves this vulnerability.Fixed in 5.1.0
Event History
Frequently Asked Questions
Does exploitation require the attacker to be on the same or an adjacent network?
Yes. The attack vector is adjacent network (AV:A), so the attacker must have access from an adjacent network context rather than exploiting it solely from an arbitrary remote Internet location.
Is user interaction required for successful exploitation?
Yes. The CVSS vector specifies user interaction required (UI:R).
What is the expected impact on confidentiality, integrity, and availability?
The CVSS vector rates confidentiality impact as high. Integrity and availability impacts are rated none.