Description
Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.
Published: 2026-08-17
Score: 6.1 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a stored cross‑site scripting vulnerability in Squirro Cognitive Search versions older than 3.14.2. It permits a remote attacker to inject and execute arbitrary code through the Email Notification, Create Evaluation Sets and HTML Editor features. Based on the description, it is inferred that the injected code runs in the context of any user who views the affected content, effectively turning the XSS into a remote code execution vector.

Affected Systems

All installations of Squirro Cognitive Search with a build earlier than 3.14.2 are affected. Versions below 3.14.2 do not sanitize or properly escape input to the Email Notification, Create Evaluation Sets, or HTML Editor components, leaving the application vulnerable.

Risk and Exploitability

The CVSS base score of 6.1 indicates medium severity. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, so the exact likelihood of exploitation is unknown. The flaw can be exploited if the endpoints that accept untrusted input are reachable; based on the description, it is inferred that the risk is higher for publicly exposed or internally exposed services that have not been restricted or patched.

Generated by OpenCVE AI on August 18, 2026 at 00:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Squirro Cognitive Search to version 3.14.2 or later.
  • Apply input sanitization or HTML escaping to content processed by the Email Notification, Create Evaluation Sets, and HTML Editor features before rendering.
  • Deploy a web‑application firewall or equivalent controls to filter or block XSS payloads sent to the affected endpoints.

Generated by OpenCVE AI on August 18, 2026 at 00:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 18 Aug 2026 01:15:00 +0000

Type Values Removed Values Added
Title Stored XSS in Squirro Cognitive Search Enables Remote Code Execution

Mon, 17 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Stored XSS in Squirro Cognitive Search Enables Remote Code Execution
Weaknesses CWE-79

Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T20:42:54.721Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50771

cve-icon Vulnrichment

Updated: 2026-08-17T20:42:49.190Z

cve-icon NVD

Status : Received

Published: 2026-08-17T18:17:09.100

Modified: 2026-08-17T21:16:45.780

Link: CVE-2026-50771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-18T01:00:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')