Vulnerability Description
The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.
CVSS Score
NONE
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-44961?
CVE-2026-44961 is a vulnerability with a CVSS score of 0.0 (NONE). The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper ...
How severe is CVE-2026-44961?
CVE-2026-44961 has been rated NONE with a CVSS base score of 0.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-44961?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.