CVE-2026-2677: Multiple vulnerabilities in A3factura software

Published Feb 26, 2026
·
Updated

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'name', in 'a3factura-app.wolterskluwer.es/#/incomes/representatives-management' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

Affected Software

2 affected components
Wolters Kluwer A3factura
wolterskluwer A3factura=4.111.2-rev.1

Remediation

Information

The fix has been deployed in production in version 4.114.0-rev.6, released on 17/02/2026.

Event History

Feb 26, 2026
CVE Published
via MITRE·12:16 PM
Data Sourced
via MITRE·12:16 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeaknessAffected Software
Oct 1, 58139
Event
via FIRST·07:48 PM

Frequently Asked Questions

1

What is CVE-2026-2677?

CVE-2026-2677 is a reflected cross-site scripting (XSS) vulnerability in the A3factura web platform that allows attackers to execute arbitrary code in users' browsers.

2

What is the severity of CVE-2026-2677?

The severity of CVE-2026-2677 is high, as it exposes users to potential code execution attacks.

3

How do I fix CVE-2026-2677?

To fix CVE-2026-2677, ensure that the A3factura software is updated to the latest version that addresses this vulnerability.

4

Who is affected by CVE-2026-2677?

Users of the A3factura software, specifically those utilizing the affected endpoint, are at risk from CVE-2026-2677.

5

What can attackers do with CVE-2026-2677?

Attackers can exploit CVE-2026-2677 to execute arbitrary scripts in the context of the victim's browser, potentially stealing sensitive information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203