CVE-2026-26352: Smoothwall Express < 3.1 Update 13 Stored XSS in vpnmain.cgi via VPN_IP Parameter
Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPNIP parameter. Authenticated attackers can inject arbitrary JavaScript through VPN configuration settings that executes when the affected page is viewed by other users.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Smoothwall Expressto a version that resolves this vulnerability.Fixed in 3.1 Update 13 - Compensating control
Restrict access to the VPN configuration so only trusted/authorized administrators can change VPN settings that affect vpnmain.cgi (mitigates stored XSS injection via VPN_IP).
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26352?
CVE-2026-26352 has a medium severity rating due to the potential for authenticated attackers to exploit the stored XSS vulnerability.
How do I fix CVE-2026-26352?
To mitigate CVE-2026-26352, upgrade Smoothwall Express to version 3.1 Update 13 or later.
Who is affected by CVE-2026-26352?
Users of Smoothwall Express versions prior to 3.1 Update 13 are affected by CVE-2026-26352.
What type of vulnerability is CVE-2026-26352?
CVE-2026-26352 is a stored cross-site scripting (XSS) vulnerability.
Can CVE-2026-26352 be exploited remotely?
CVE-2026-26352 requires authentication for exploitation, meaning it cannot be exploited remotely without valid credentials.