CVE-2026-71802
Last modified
CVE-2026-71802 is a medium-severity vulnerability rated 5.4/10 on the CVSS scale. A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Although the announcement content undergoes HTML escaping on the server side, the client-side preview code reverses the escaped entities using jQuery's `html().text()` method and subsequently injects the result into the DOM. EPSS estimates a 0.15% chance of exploitation in the next 30 days.
Description
A stored Cross-Site Scripting (XSS) vulnerability exists in the announcement preview component of REBUILD 4.4.3. Although the announcement content undergoes HTML escaping on the server side, the client-side preview code reverses the escaped entities using jQuery's `html().text()` method and subsequently injects the result into the DOM. An administrator or attacker capable of controlling the announcement content can exploit this vulnerability to execute arbitrary JavaScript code in the browsers of users viewing the affected pages "which may include the dashboard, activity feed, or login page, depending on the announcement's visibility settings.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| — | — | n/a |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-71802?
How severe is CVE-2026-71802?
How do I fix CVE-2026-71802?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71693Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: non…
- CVE-2026-71694An issue in Berkeley Out-of-Order Machine (BOOM) / BoomTile …8.8
- CVE-2026-7177A security flaw has been discovered in ChatGPTNextWeb NextCh…7.3
- CVE-2026-7178A weakness has been identified in ChatGPTNextWeb NextChat up…7.3
- CVE-2026-7179A security vulnerability has been detected in OSPG binwalk u…5.3
- CVE-2026-71801An issue was discovered in s-pms SPMS-Server through v1.0. T…9.8
- CVE-2026-71803money-pos 1.0 contains a stored Cross-Site Scripting (XSS) v…5.4
- CVE-2026-71805An arbitrary file upload and path traversal vulnerability ex…9.8
- CVE-2026-71807In RuoYi-Cloud-Plus <= 2.6.2 in the ruoyi-workflow module, m…4.3
- CVE-2026-71808A SQL Injection vulnerability in Siam Ordering (siam-server)…8.8
- CVE-2026-71809Authentication Bypass via Hardcoded Master Verification Code…8.1
- CVE-2026-7182Diagram's export module is vulnerable to Path Traversal in s…9.2
Are you affected by CVE-2026-71802?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
