Description
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.This issue affects Sentinel LDK Runtime: before 10.22.
Published: 2026-03-27
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting (execution of attacker scripts in victims' browsers)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from improper neutralization of input during web page generation in Thales Sentinel LDK Runtime for Windows. An attacker can inject malicious scripts that are stored and later rendered in a victim’s browser, allowing execution of arbitrary JavaScript. This stored Cross‑Site Scripting can lead to session hijacking, theft of confidential information, and defacement or manipulation of the user interface. The weakness is classified as CWE‑79, indicating an XSS flaw that compromises the confidentiality and integrity of any data accessed through the affected page.

Affected Systems

The issue affects the Sentinel LDK Runtime product from Thales on Windows platforms. All releases prior to version 10.22 are vulnerable. This includes any deployment of the LDK Runtime that processes user‑supplied input without proper sanitization, regardless of deployment size or tenant environment.

Risk and Exploitability

The CVSS score of 7 signals a high severity, meaning the flaw could have significant impact if exploited. No EPSS score is published, and the vulnerability is not listed in CISA’s KEV catalog, suggesting no known publicly available exploits yet, but the potential for exploitation remains. Attackers could leverage the web interface that stores user data to deliver malicious payloads; the ability to perform the attack remotely, coupled with the stored nature of the data, makes it attractive to threat actors who have the capacity to inject content that will be served to other users.

Generated by OpenCVE AI on March 27, 2026 at 10:35 UTC.

Remediation

Vendor Solution

Upgrade current Sentinel LDK Runtime to version 10.22 or higher.


OpenCVE Recommended Actions

  • Upgrade Sentinel LDK Runtime to version 10.22 or newer.

Generated by OpenCVE AI on March 27, 2026 at 10:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 27 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 27 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.This issue affects Sentinel LDK Runtime: before 10.22.
Title Stored XSS vulnerability in Sentinel ACC
First Time appeared Thales
Thales sentinel Ldk Runtime
Weaknesses CWE-79
CPEs cpe:2.3:a:thales:sentinel_ldk_runtime:*:*:windows:*:*:*:*:*
Vendors & Products Thales
Thales sentinel Ldk Runtime
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:P'}


Subscriptions

Thales Sentinel Ldk Runtime
cve-icon MITRE

Status: PUBLISHED

Assigner: THA-PSIRT

Published:

Updated: 2026-03-27T13:45:21.259Z

Reserved: 2026-03-02T19:33:17.694Z

Link: CVE-2026-3457

cve-icon Vulnrichment

Updated: 2026-03-27T13:06:25.777Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-27T09:16:20.543

Modified: 2026-03-30T13:26:29.793

Link: CVE-2026-3457

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-03-30T07:02:10Z

Weaknesses