CVE-2026-24050
Last modified
CVE-2026-24050 is a low-severity vulnerability rated 1.1/10 on the CVSS scale. Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
Zulip is an open-source team collaboration tool. From 5.0 to before 11.5, some administrative actions on the user profile were susceptible to stored XSS in group names or channel names. Exploiting these vulnerabilities required the user explicitly interacting with the problematic object. This vulnerability is fixed in 11.5.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Zulip | Zulip Server | >= 5.0, < 11.5 |
References
- https://github.com/zulip/zulip/releases/tag/11.5Release Notes
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-24050?
How severe is CVE-2026-24050?
How do I fix CVE-2026-24050?
Are you affected by CVE-2026-24050?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
