CVE-2026-87752: HTML Injection in Rolantis Information Technologies' Agentis
Published Sep 28, 2026
·Updated
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Rolantis Information Technologies Tourism Industry and Trade Co. Ltd. Agentis allows XSS Targeting HTML Attributes.
This issue affects Agentis: from 4.44 before 4.6.
Affected Software
1 affected component
Rolantis Information Technologies Agentis>=4.44<4.6
Event History
Sep 28, 2026
CVE Published
via MITRE·11:34 AM
Data Sourced
via MITRE·11:34 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated Agentis account or a complex attack path?
No privileges are required, and the attack complexity is rated low. However, exploitation requires user interaction, meaning a target must interact with attacker-controlled content.
2
What is the expected security impact if the issue is exploited?
The CVSS vector indicates low-impact confidentiality and integrity effects, with no availability impact. It also marks the scope as changed, although the available data does not identify which additional component or security authority may be affected.