CVE-2026-15639

Summary

An attacker can craft a malicious link that, if used by a legitimate user, may cause the user's browser to run JavaScript supplied by the attacker.

Affected Software

VendorProductVersion RangeStatus
DelineaSecret Server (On-Prem)10.2.19 <= 11.9.48affected

Weaknesses

  • CWE-79: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')

References