CVE-2026-8152

Summary

Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.

When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript injected through this vulnerability therefore executes with full access to the host application's cookies, DOM, and same-origin APIs — an attacker can reach all resources of the host application, not just Unblu's. This expanded blast radius is the reason on-premises deployments using this configuration are rated CRITICAL.

Affected Software

VendorProductVersion RangeStatus
Unblu inc.Unblu Spark0 <= 8.36.1affected
Unblu inc.Unblu Spark8.36.1-hotfix.0unaffected
Unblu inc.Unblu Spark8.37.0unaffected

Weaknesses

  • CWE-601: CWE-601 URL Redirection to Untrusted Site ('Open Redirect')
  • CWE-79: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Workarounds

If you cannot upgrade immediately, either of the following measures prevents exploitation:

  • Enable the built-in Content Security Policy by setting com.unblu.contentsecuritypolicy.mode=on. The CSP blocks the injected JavaScript from executing and prevents the exploit from succeeding. Note: this protection is only effective on Unblu Spark 7.56.2 or later in the 7.x series and 8.19.1 or later in the 8.x series, where unsafe-inline was removed from the script source policy. Earlier versions ship a CSP that still permits unsafe-inline and are not protected by this workaround.
  • Configure a WAF rule to block requests that carry a malicious payload in the redirectOnFailure parameter (in particular, values containing a javascript: scheme or obfuscated variants such as java%0ascript:).

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References