Back

MEDIUM

HTML injection in Users in Guardian/CMC before 26.1.0

Published May 19, 2026

Description

A Stored HTML Injection vulnerability was discovered in the Users functionality due to improper validation of an input parameter. An authenticated user with administrative privileges can create a malicious user whose username contains HTML tags. When a victim attempts to delete a group containing the affected user, the injected HTML renders in their browser, enabling phishing and possibly open redirect attacks. Full XSS exploitation and direct information disclosure are prevented by the existing input validation and Content Security Policy configuration.

Affected products

Remediation

Vendor solution

Upgrade to v26.1.0 or later.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Nozomi
Published May 19, 2026
Updated Aug 11, 2026
Reserved Apr 16, 2025
CISA Vulnrichment
Updated May 19, 2026
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a