CVE-2026-4765
Last modified
CVE-2026-4765 is a none-severity vulnerability. Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in the ‘name’ parameter of the initialisation process due to incorrect sanitisation of user-supplied input. EPSS estimates a 0.44% chance of exploitation in the next 30 days.
Description
Self Cross-Site Scripting (Self-XSS) vulnerability in the RD Station Conversas chat feature. The vulnerability lies in the ‘name’ parameter of the initialisation process due to incorrect sanitisation of user-supplied input. Exploitation allows specially crafted JavaScript code to be injected, which is executed within the context of the user’s own session who provides the payload. The demonstrated impact is limited to the user who enters and executes the payload.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| RD Station Conversas | Tallos Chat | all versions |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-4765?
How severe is CVE-2026-4765?
How do I fix CVE-2026-4765?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-47643External control of file name or path in Azure Stack Edge al…9.8
- CVE-2026-47644Improper neutralization of special elements in output used b…7.5
- CVE-2026-47645Url redirection to untrusted site ('open redirect') in Micro…8.8
- CVE-2026-47646Improper neutralization of input during web page generation …6.1
- CVE-2026-47647Improper access control in Microsoft Dynamics 365 allows an …9.9
- CVE-2026-47648Untrusted search path in Windows Storage allows an authorize…7
- CVE-2026-47652Heap-based buffer overflow in Windows Hyper-V allows an auth…8.2
- CVE-2026-47653Use after free in Remote Desktop Client allows an unauthoriz…8.8
- CVE-2026-47654Use after free in Remote Desktop Client allows an unauthoriz…7.5
- CVE-2026-47655Exposure of sensitive information to an unauthorized actor i…6.5
- CVE-2026-47656Protection mechanism failure in Windows Boot Manager allows …7.9
- CVE-2026-47657HumHub is an Open Source Enterprise Social Network. In versi…7.1
Are you affected by CVE-2026-4765?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
