Loading market data...
← Back to CVE feed

CVE-2026-23926

UNKNOWN View on NVD ↗

Description

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

Published: May 06, 2026 08:16 UTC Modified: May 06, 2026 08:16 UTC