CVE-2026-4186
Last modified
CVE-2026-4186 is a low-severity vulnerability rated 3.5/10 on the CVSS scale. A vulnerability was determined in UEditor up to 1.4.3.2. This issue affects some unknown processing of the file php/controller.php?action=uploadimage of the component JSONP Callback Handler. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A vulnerability was determined in UEditor up to 1.4.3.2. This issue affects some unknown processing of the file php/controller.php?action=uploadimage of the component JSONP Callback Handler. This manipulation of the argument callback causes cross site scripting. The attack can be initiated remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. This vulnerability only affects products that are no longer supported by the maintainer.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-4186?
How severe is CVE-2026-4186?
How do I fix CVE-2026-4186?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-41854Due to incorrect host parsing, applications that rely on Uri…6.5
- CVE-2026-41855In an untrusted JMS environment, org.springframework.jms.sup…9.8
- CVE-2026-41856The Spring GraphQL annotation detection mechanism for @Contr…7.5
- CVE-2026-41857A compromised or malicious BOSH Director can execute arbitra…7.8
- CVE-2026-41858Weak Randomness / Insecure Cryptographic Primitive (CWE-338)…7.5
- CVE-2026-41859A network man-in-the-middle between nats-sync and the BOSH d…7.8
- CVE-2026-41860CWE-326 in BOSH allows a local attacker to steal Basic-auth …8.8
- CVE-2026-41861Path Traversal in BOSH-Ecosystem / BOSH allows an IaaS-metad…4.2
- CVE-2026-41862Spring Statemachine's Kryo-based persistence backends (JPA, …8.8
- CVE-2026-41863Spring AI's support for Anthropic's Skills API used LLM-infl…6.5
- CVE-2026-4187A vulnerability was identified in Tiandy Easy7 Integrated Ma…5.5
- CVE-2026-41872"Kura Sushi Official App" provided by EPG, Inc. is vulnerabl…9.1
Are you affected by CVE-2026-4186?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
