CVE-2026-1434

MEDIUM

Omega-PSIR 4.5.9-4.6.7 - Reflected Cross-Site Scripting via Lang Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-1434. PoCs published by lukasz-rybak.

AI-analyzed exploit summary This repository provides a detailed technical writeup for CVE-2026-1434, a Reflected XSS vulnerability in Omega-PSIR via the 'lang' parameter. It includes CWE classification, references, and a clear description of the issue.

Description

Omega-PSIR is vulnerable to Reflected XSS via the lang parameter. An attacker can craft a malicious URL that, when opened, causes arbitrary JavaScript to execute in the victim’s browser. This issue was fixed in 4.6.7.

Exploits (1)

nomisec WRITEUP
by lukasz-rybak · poc
https://github.com/lukasz-rybak/CVE-2026-1434

This repository provides a detailed technical writeup for CVE-2026-1434, a Reflected XSS vulnerability in Omega-PSIR via the 'lang' parameter. It includes CWE classification, references, and a clear description of the issue.

Classification
Writeup 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Omega-PSIR (versions prior to 4.6.7)
No auth needed
Prerequisites: Victim must open a crafted malicious URL
devstral-2 · analyzed Apr 12, 2026 Full analysis →

References (2)

Core 2
Core References
Various Sources third-party-advisory
https://cert.pl/posts/2026/02/CVE-2026-1434
Various Sources product
https://www.omegapsir.io/

Scores

CVSS v3 6.1
EPSS 0.0016
EPSS Percentile 5.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
pw/omega-psir 4.5.9 - 4.6.7
Published Feb 27, 2026
Tracked Since Feb 27, 2026