THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-23926 (MEDIUM 6.8) — An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on

[NVD] CVE-2026-23926 (MEDIUM 6.8) — An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on

lownvdPublished 2026-05-06

CVE-2026-23926 CVSS: 6.8 MEDIUM Published: 2026-05-06T08:16:01.837

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-23926