CVE-2026-20711: XSS
Published Feb 2, 2026
·Updated
Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.
Affected Software
2 affected components
Cybozu Garoon>=5.0.0<6.0.3
Cybozu Garoon>=5.0.0<6.0.3
Event History
Feb 2, 2026
CVE Published
via MITRE·06:37 AM
Data Sourced
via MITRE·06:37 AM
DescriptionSeverity
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-20711?
CVE-2026-20711 is a medium-severity cross-site scripting vulnerability in Cybozu Garoon.
2
How do I fix CVE-2026-20711?
To fix CVE-2026-20711, upgrade Cybozu Garoon to version 6.0.4 or later.
3
What impact does CVE-2026-20711 have on users?
CVE-2026-20711 may allow an attacker to reset arbitrary users' passwords through the E-mail function.
4
Which versions of Cybozu Garoon are affected by CVE-2026-20711?
CVE-2026-20711 affects Cybozu Garoon versions 5.0.0 to 6.0.3.
5
Is CVE-2026-20711 easy to exploit?
Yes, CVE-2026-20711 can be exploited relatively easily due to its dependence on the E-mail function.