CVE-2026-32866: OPEXUS eComplaint and eCase stored XSS via profile first and last name
OPEXUS eComplaint and eCASE before 10.2.0.0 do not correctly sanitize the contents of first and last name fields in a user profile. An authenticated attacker can inject parts of an XSS payload in their first and last name fields. The payload is executed when the user's full name is rendered. The attacker can run script in the context of a victim's session.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-32866?
CVE-2026-32866 is a stored Cross-Site Scripting (XSS) vulnerability that can allow an attacker to execute arbitrary scripts in the context of a user's session.
How do I fix CVE-2026-32866?
To fix CVE-2026-32866, update OPEXUS eComplaint and eCASE to version 10.2.0.0 or later, which includes proper sanitization of user profile fields.
Who is affected by CVE-2026-32866?
CVE-2026-32866 affects users of OPEXUS eComplaint and eCASE versions prior to 10.2.0.0.
What kind of attack can be executed via CVE-2026-32866?
An attacker can inject malicious scripts through the first and last name fields in a user profile, potentially compromising user sessions.
Is user authentication required to exploit CVE-2026-32866?
Yes, an attacker must be authenticated to exploit CVE-2026-32866 and inject an XSS payload in the profile fields.