Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.

This issue affects Sentinel LDK Runtime: before 10.22.
Published: 2026-03-27
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (execution of attacker scripts in victims' browsers)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an improper neutralization of input during web page generation in Thales Sentinel LDK Runtime on Windows, leading to stored cross‑site scripting. An attacker can embed malicious JavaScript that will be automatically rendered when users view the affected page, enabling local script execution. This can result in session hijacking, data theft, defacement, and manipulation of the user interface. The flaw is classified as CWE‑79.

Affected Systems

The issue affects the Sentinel LDK Runtime product from Thales, deployed on Windows. Versions older than 10.22 are vulnerable.

Risk and Exploitability

The CVSS score of 7 signals a high severity, while the EPSS score of < 1 % indicates a low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. It is inferred that the attack vector is the web interface that accepts user input; an attacker could inject malicious content via submitted payloads. The stored nature of the payload allows it to be served to any user who views the affected page until the application is patched or the data is removed.

Generated by OpenCVE AI on August 27, 2026 at 00:08 UTC.

Remediation

Vendor Solution

Upgrade current Sentinel LDK Runtime to version 10.22 or higher.


OpenCVE Recommended Actions

  • Upgrade Sentinel LDK Runtime to version 10.22 or newer.
  • Ensure that any data stored by the application is sanitized or validated to remove executable scripts before being rendered.
  • Configure a strict Content Security Policy header that forbids inline script execution and blocks external script sources to mitigate impact if the upgrade cannot be applied immediately.

Generated by OpenCVE AI on August 27, 2026 at 00:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Thalesgroup
Thalesgroup sentinel Ldk Runtime
CPEs cpe:2.3:a:thales:sentinel_ldk_runtime:*:*:windows:*:*:*:*:* cpe:2.3:a:thalesgroup:sentinel_ldk_runtime:*:*:windows:*:*:*:*:*
Vendors & Products Thalesgroup
Thalesgroup sentinel Ldk Runtime

Wed, 26 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.This issue affects Sentinel LDK Runtime: before 10.22. Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22.
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N'}


Fri, 27 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.This issue affects Sentinel LDK Runtime: before 10.22.
Title Stored XSS vulnerability in Sentinel ACC
First Time appeared Thales
Thales sentinel Ldk Runtime
Weaknesses CWE-79
CPEs cpe:2.3:a:thales:sentinel_ldk_runtime:*:*:windows:*:*:*:*:*
Vendors & Products Thales
Thales sentinel Ldk Runtime
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:P'}


Subscriptions

Thales Sentinel Ldk Runtime
Thalesgroup Sentinel Ldk Runtime
cve-icon MITRE

Status: PUBLISHED

Assigner: THA-PSIRT

Published:

Updated: 2026-09-03T15:44:12.227Z

Reserved: 2026-03-02T19:33:17.694Z

Link: CVE-2026-3457

cve-icon Vulnrichment

Updated: 2026-03-27T13:06:25.777Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-27T09:16:20.543

Modified: 2026-09-03T16:17:23.907

Link: CVE-2026-3457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T00:15:07Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')