CVE-2026-18682: OpenAkita File Upload API upload cross site scripting
A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipulation of the argument File results in cross site scripting. The attack may be performed from remote. A high complexity level is associated with this attack. It is stated that the exploitability is difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-18682?
The severity of CVE-2026-18682 is classified as low with a score of 3.1.
How do I fix CVE-2026-18682?
To fix CVE-2026-18682, update OpenAkita to the latest version that addresses this vulnerability.
What type of vulnerability is CVE-2026-18682?
CVE-2026-18682 is a cross-site scripting vulnerability affecting the OpenAkita File Upload API.
What component is affected by CVE-2026-18682?
CVE-2026-18682 affects the /api/upload component of the OpenAkita File Upload API.
Can CVE-2026-18682 be exploited remotely?
Yes, CVE-2026-18682 can be exploited remotely due to the nature of the vulnerability.