CVE-2026-22233: OPEXUS eCASE Audit Project Cost stored XSS
OPEXUS eCASE Audit allows an authenticated attacker to save JavaScript as a comment in the "Estimated Staff Hours" field. The JavaScript is executed whenever another user visits the Project Cost tab. Fixed in OPEXUS eCASE Audit 11.14.2.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-22233?
CVE-2026-22233 is classified as a high-severity vulnerability due to its potential for cross-site scripting (XSS) attacks.
How do I fix CVE-2026-22233?
To fix CVE-2026-22233, upgrade to OPEXUS eCASE Audit version 11.14.2.0 or later.
What impact does CVE-2026-22233 have on users?
CVE-2026-22233 allows an authenticated attacker to execute malicious JavaScript in the context of other users, compromising their session.
Who is affected by CVE-2026-22233?
CVE-2026-22233 affects all versions of OPEXUS eCASE Audit prior to 11.14.2.0.
Is there a workaround for CVE-2026-22233?
Currently, there is no known effective workaround for CVE-2026-22233 other than applying the security update.