CVE-2026-3278: XSS Vulnerability discovered in OpenText™ ZENworks Service Desk.
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execute arbitrary JavaScript leading to unauthorized actions on behalf of the user.This issue affects ZENworks Service Desk: 25.2, 25.3.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3278?
CVE-2026-3278 is classified as a high severity vulnerability due to its potential for allowing cross-site scripting attacks.
How do I fix CVE-2026-3278?
To fix CVE-2026-3278, update OpenText™ ZENworks Service Desk to a version later than 25.3.
What is the impact of CVE-2026-3278?
CVE-2026-3278 can allow attackers to execute arbitrary JavaScript in the context of a user's browser, leading to potential data theft or session hijacking.
Which versions of OpenText™ ZENworks Service Desk are affected by CVE-2026-3278?
Versions 25.2 to 25.3 of OpenText™ ZENworks Service Desk are affected by CVE-2026-3278.
How can I determine if my systems are vulnerable to CVE-2026-3278?
To determine vulnerability to CVE-2026-3278, check if you are running OpenText™ ZENworks Service Desk version 25.2 to 25.3.