NONE · 0

CVE-2026-90443

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenti...

Vulnerability Description

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-90443?

CVE-2026-90443 is a documented vulnerability. A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenti...

How severe is CVE-2026-90443?

CVSS scoring is not yet available for CVE-2026-90443. Check NVD for updates.

Is there a patch for CVE-2026-90443?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.