CVE-2026-22674
MEDIUMHashgraph Guardian Stored XSS via branding companyName field
Title source: cnaDescription
Hashgraph Guardian through 3.5.0, fixed in commit ba8c566, contains a stored cross-site scripting vulnerability that allows authenticated users with the STANDARD_REGISTRY role to inject malicious scripts by submitting a crafted companyName value via the branding configuration API endpoint. Attackers can exploit the unsanitized innerHTML assignment in the branding service to execute arbitrary JavaScript in the browser of every authenticated user on every page load.
References (3)
Core 3
Core References
Issue Tracking issue-tracking
https://github.com/hashgraph/guardian/pull/6190
Third Party Advisory third-party-advisory
https://www.vulncheck.com/advisories/hashgraph-guardian-stored-xss-via-branding-companyname-field
Scores
CVSS v3
4.8
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Details
CWE
CWE-79
Status
published
Products (2)
hashgraph/guardian
< 3.6.0
hashgraph/guardian
ba8c566807848cf84360716438056d8d8d2c8362
Published
Jun 18, 2026
Tracked Since
Jun 19, 2026