CVE-2026-14466
EUVD-2026-7121804.09.2026, 15:17
It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject some malicious script in a group’s comments in the webservices administration interface.
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| stormshield | network_security | 4.8.0 ≤ 𝑥 ≤ 4.8.16 | CNA |
| stormshield | network_security | 5.0.0 ≤ 𝑥 ≤ 5.0.6 | CNA |