Description
A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session.
Published: 2026-08-11
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A DOM‑based Cross‑Site Scripting flaw exists in the web portals of BlackBerry AtHoc IWS versions before 7.21 HF‑734. The vulnerability allows a malicious actor to inject and execute arbitrary JavaScript while a user is browsing an AtHoc portal, potentially resulting in cookie theft, session hijacking, or execution of unwanted actions in the victim’s session. The weakness is a client‑side code injection flaw catalogued as CWE‑79.

Affected Systems

BlackBerry AtHoc IWS, specifically the AtHoc Web Portal component of the IWS platform. Versions earlier than 7.21 HF‑734 are affected; newer releases are not listed as vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate risk, and the EPSS score of less than 1% suggests low current exploitation likelihood. Because the attack requires the user to click a crafted link or access a malicious page, the attack vector is remote via the web interface, and the vulnerability is not listed in CISA’s KEV catalog. If exploited, the attacker can perform client‑side actions under the victim’s authenticated context, but cannot directly compromise the underlying server or elevate privileges.

Generated by OpenCVE AI on August 12, 2026 at 21:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update BlackBerry AtHoc IWS to version 7.21 HF‑734 or later to remove the DOM‑based XSS flaw.
  • If an upgrade is not immediately possible, disable or restrict the use of the affected web portal features that process unsanitized input, and enforce strict content‑security policies to block the injection of inline scripts.
  • Educate users to avoid clicking suspicious URLs and deploy web‑application firewalls that detect and block script payloads targeting the AtHoc portal.

Generated by OpenCVE AI on August 12, 2026 at 21:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:00:00 +0000

Type Values Removed Values Added
First Time appeared Blackberry
Blackberry blackberry Os
Vendors & Products Blackberry
Blackberry blackberry Os

Tue, 11 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session.
Title DOM-Based Cross-Site Scripting in BlackBerry AtHoc Web Portals
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N'}


Subscriptions

Blackberry Blackberry Os
cve-icon MITRE

Status: PUBLISHED

Assigner: blackberry

Published:

Updated: 2026-08-11T16:49:34.883Z

Reserved: 2026-07-29T14:59:50.726Z

Link: CVE-2026-18247

cve-icon Vulnrichment

Updated: 2026-08-11T16:49:19.324Z

cve-icon NVD

Status : Received

Published: 2026-08-11T17:17:48.220

Modified: 2026-08-11T17:17:48.220

Link: CVE-2026-18247

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:41:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')