CVE-2026-2680: Multiple vulnerabilities in A3factura software
Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2680?
CVE-2026-2680 is classified as a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2026-2680?
To fix CVE-2026-2680, ensure that the A3factura software is updated to the latest version provided by Wolters Kluwer that patches the XSS vulnerabilities.
What type of vulnerability is CVE-2026-2680?
CVE-2026-2680 is a reflected cross-site scripting (XSS) vulnerability affecting the A3factura web platform.
Where is CVE-2026-2680 located in the A3factura software?
CVE-2026-2680 is found in the 'customerVATNumber' parameter on the a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes endpoint.
Who is affected by CVE-2026-2680?
Users of the A3factura software platform are at risk due to CVE-2026-2680, as it can allow attackers to execute malicious code.