CVE-2026-90443: XSS

Published Sep 11, 2026
·
Updated

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.

Event History

Sep 11, 2026
CVE Published
via MITRE·09:45 PM
Data Sourced
via MITRE·09:45 PM
RemedyDescriptionWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Any user who visits an attacker-crafted link to the affected application's web interface may be exposed. The vulnerable interface is reachable without authentication, but the impact of script execution depends on the session privileges of the user who follows the link.

2

What does an attacker need to exploit it?

An attacker needs network access to reach the web interface and must persuade a user to visit a crafted URL. No authentication is required to access the vulnerable interface.

3

What can happen if exploitation succeeds?

The attacker can execute arbitrary script in the affected application's browser context and redirect the user's browser to an external site. They may be able to act within the application using the compromised user's session privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203