CVE-2026-14466
4.3
CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Summary
It’s possible to run a stored XSS in Stormshield’s web administration panel.
To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Stormshield | Stormshield Network Security | 4.8.0 <= 4.8.16 | affected |
| Stormshield | Stormshield Network Security | 5.0.0 <= 5.0.6 | affected |
| Stormshield | Stormshield Network Security | 4.8.17 | unaffected |
| Stormshield | Stormshield Network Security | 5.0.7 | unaffected |
| Stormshield | Stormshield Network Security | 5.1.0 | unaffected |
Weaknesses
- CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.