Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 17 Aug 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 21:15:00 +0000

Type Values Removed Values Added
Title Stored XSS in Squirro Cognitive Search Enables Remote Code Execution
Weaknesses CWE-79

Mon, 17 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting vulnerability in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbtirary code via the Email Notification, Create Evaluation Sets and HTML Editor functions.
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T20:42:54.721Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50771

cve-icon Vulnrichment

Updated: 2026-08-17T20:42:49.190Z

cve-icon NVD

Status : Received

Published: 2026-08-17T18:17:09.100

Modified: 2026-08-17T21:16:45.780

Link: CVE-2026-50771

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T21:00:14Z

Weaknesses