CVE-2026-8474

MEDIUM

Possible to run a Cross Site Scripting request on the login API available on Stormshield SNS appliances.

Title source: cna
STIX 2.1

Description

A vulnerability was discovered on Stormshield Network Security  * 4.3.0 to 4.3.41,  * 4.8.0 to 4.8.15,  * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page behavior, for example, by redirecting the victim to malicious websites.

References (1)

Core 1

Scores

CVSS v3 5.3
EPSS 0.0018
EPSS Percentile 8.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (3)
StormShield/StormShield Network Security 4.3.0 - 4.3.41
StormShield/StormShield Network Security 4.8.0 - 4.8.15
StormShield/StormShield Network Security 5.0.0 - 5.0.5
Published Jun 01, 2026
Tracked Since Jun 01, 2026