Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-23926

UNKNOWN NVD
CVSS Score 0
Severity UNKNOWN
Published May 06, 2026
Vendor unknown

Description

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

References