THREAT OPS › Threat News › [NVD] CVE-2026-23926 (MEDIUM 6.8) — An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on
[NVD] CVE-2026-23926 (MEDIUM 6.8) — An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on
CVE-2026-23926 CVSS: 6.8 MEDIUM Published: 2026-05-06T08:16:01.837
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-23926cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-23926