Description
It’s possible to run a stored XSS in Stormshield’s web administration panel.



To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.
Published: 2026-09-04
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch
AI Analysis

Impact

The vulnerability allows a malicious script to be stored in the web administration panel of Stormshield SNS. An attacker who can inject a script into a group’s comments can cause that script to run whenever an administrator views the comment.

Affected Systems

The issue impacts Stormshield Network Security’s SNS product. Versions prior to SNS 5.1.0, SNS 5.0.7, and SNS 4.8.17 are vulnerable; updates to those releases provide the fix.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an administrator with sufficient permissions to inject the script; the vulnerability is not exploitable by unauthenticated users.

Generated by OpenCVE AI on September 4, 2026 at 16:02 UTC.

Remediation

Vendor Solution

The following updates will fix this vulnerability: * SNS 5.1.0 * SNS 5.0.7 * SNS 4.8.17


OpenCVE Recommended Actions

  • Upgrade SNS to version 5.1.0, 5.0.7, or 4.8.17 as provided by the vendor
  • Limit administrative privileges to trusted users only to reduce the opportunity for script injection
  • Implement input validation and output encoding for comment fields to mitigate future XSS attempts

Generated by OpenCVE AI on September 4, 2026 at 16:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Fri, 04 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Stormshield
Stormshield stormshield Network Security
Vendors & Products Stormshield
Stormshield stormshield Network Security

Fri, 04 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 04 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.
Title Possible XSS in the SNS web administration panel
Weaknesses CWE-79
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N'}


Subscriptions

Stormshield Stormshield Network Security
cve-icon MITRE

Status: PUBLISHED

Assigner: airbus

Published:

Updated: 2026-09-04T14:41:07.268Z

Reserved: 2026-07-02T12:42:10.025Z

Link: CVE-2026-14466

cve-icon Vulnrichment

Updated: 2026-09-04T14:40:59.135Z

cve-icon NVD

Status : Deferred

Published: 2026-09-04T15:17:32.540

Modified: 2026-09-08T14:03:48.663

Link: CVE-2026-14466

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T16:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')