Description
A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript content into the fields containing their personal data. The content entered is stored and displayed without being properly sanitised when another user, including administrative staff, views the affected profile. Successful exploitation could allow JavaScript code to be executed in the victim’s browser, access to information available within the session, or the performance of actions using the victim’s permissions.
Published: 2026-09-18
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stored cross‑site scripting that allows execution of arbitrary JavaScript in the victim’s browser
Action: Patch immediately
AI Analysis

Impact

A stored cross‑site scripting vulnerability exists in the profile management component of T‑Systems TAO 2.0. An authenticated user can inject malicious HTML or JavaScript into their personal data fields. The application then stores and renders this content without sanitisation whenever another user, including administrators, views the profile, which can lead to arbitrary script execution in the victim’s browser, exposure of session data, or the execution of actions with the victim’s privileges.

Affected Systems

All installations of T‑Systems TAO 2.0 are affected, including the default 2.0 release running on any supported platform. The vulnerability was fixed in release 2602.0.0; upgrading to that version or later removes the flaw.

Risk and Exploitability

The CVSS score is 5.1, indicating a moderate severity, while the EPSS score is below 1 %, suggesting a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalogue. Exploitation requires a legitimate authenticated account to create the malicious content, followed by another user viewing the edited profile. Once this sequence is achieved, the attacker can run JavaScript in the victim’s browser and potentially hijack the session or perform privileged actions on behalf of the victim.

Generated by OpenCVE AI on September 19, 2026 at 19:58 UTC.

Remediation

Vendor Solution

The vulnerability has been fixed in version 2602.0.0.


OpenCVE Recommended Actions

  • Upgrade T‑Systems TAO to version 2602.0.0 or newer to apply the vendor patch that fixes the stored XSS flaw.
  • If an upgrade is not immediately possible, implement input validation for profile fields: strip or encode any script tags, event handlers and other executable markup before storing the data.
  • Restrict editing of personal data fields to a privileged subset of users and regularly audit profile content for malicious markup as a temporary control.

Generated by OpenCVE AI on September 19, 2026 at 19:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
Description A stored Cross-Site Scripting (XSS) vulnerability in the profile management functionality of T-Systems’ TAO 2.0 suite. An authenticated user could inject malicious HTML or JavaScript content into the fields containing their personal data. The content entered is stored and displayed without being properly sanitised when another user, including administrative staff, views the affected profile. Successful exploitation could allow JavaScript code to be executed in the victim’s browser, access to information available within the session, or the performance of actions using the victim’s permissions.
Title Stored Cross-Site Scripting (XSS) in T-Systems’ TAO 2.0
First Time appeared T-systems
T-systems tao
Weaknesses CWE-613
CPEs cpe:2.3:a:t-systems:tao:2.0:*:*:*:*:*:*:*
Vendors & Products T-systems
T-systems tao
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-09-18T10:38:25.576Z

Reserved: 2026-09-17T13:39:16.540Z

Link: CVE-2026-92976

cve-icon Vulnrichment

Updated: 2026-09-18T10:38:20.267Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T10:17:08.130

Modified: 2026-09-18T19:21:49.497

Link: CVE-2026-92976

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T20:00:14Z

Weaknesses
  • CWE-613

    Insufficient Session Expiration