CVE-2026-5696: Multiple vulnerabilities in the Microweber administration panel
Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker to perform actions without the victim’s consent, steal confidential information or hijack the user’s session.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Authenticated users of the Microweber administration panel are the targets. An attacker must convince such a user to load a request to the /admin/settings endpoint containing a malicious group parameter.
What could an attacker do if the exploit succeeds?
The attacker-controlled JavaScript runs in the authenticated victim’s browser. This can enable actions without the user’s consent, access to confidential information, or session hijacking.