CVE-2026-22674
Last modified
CVE-2026-22674 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the unsanitized innerHTML assignment in the branding service to execute arbitrary JavaScript in the browser of every authenticated user on every page load.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Hashgraph Guardian through 3.6.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the unsanitized innerHTML assignment in the branding service to execute arbitrary JavaScript in the browser of every authenticated user on every page load.
Metrics
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-22674?
How severe is CVE-2026-22674?
How do I fix CVE-2026-22674?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-22661prompts.chat prior to commit 0f8d4c3 contains a path travers…8.6
- CVE-2026-22662prompts.chat prior to commit 1464475 contains a blind server…5.3
- CVE-2026-22663prompts.chat prior to commit 7b81836 contains multiple autho…8.7
- CVE-2026-22664prompts.chat prior to commit 30a8f04 contains a server-side …7.7
- CVE-2026-22665prompts.chat prior to commit 1464475, contains an identity c…8.6
- CVE-2026-22666Dolibarr ERP/CRM versions prior to 23.0.2 contain an authent…8.6
- CVE-2026-22675OCS Inventory NG Server version 2.12.3 and prior contain a s…6.1
- CVE-2026-22676Barracuda RMM versions prior to 2025.2.2 contain a privilege…8.5
- CVE-2026-22677Hermes WebUI prior to 0.51.44 contains a path traversal vuln…6.5
- CVE-2026-22678Webmin before 2.641 contains a stored cross-site scripting v…5.4
- CVE-2026-22679Weaver (Fanwei) E-cology 10.0 versions prior to 20260312 con…9.8
- CVE-2026-2268The Ninja Forms plugin for WordPress is vulnerable to Sensit…7.5
Are you affected by CVE-2026-22674?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
