LOWVulnerability

CVE-2026-90443

A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application.

Properties

cve_id
CVE-2026-90443
signal_observed_at
2026-09-21T23:07:07+00:00
published_at
2026-09-11T22:16:46.247
last_modified
2026-09-18T19:40:31.053

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-90443 — Ninja Signal Threat Intelligence | Ninja Signal