PT-2026-22226 · Osctrl · Osctrl

Kwangyun

+1

·

Published

2026-02-26

·

Updated

2026-03-25

·

CVE-2026-28280

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions osctrl versions prior to 0.5.0
Description osctrl is an osquery management solution. A stored cross-site scripting (XSS) issue exists in the osctrl-admin on-demand query list. A user with query-level permissions can inject arbitrary JavaScript via the query parameter when running an on-demand query. The payload is stored and executes in the browser of any user, including administrators, who visits the query list page. This can be combined with Cross-Site Request Forgery (CSRF) token extraction to escalate privileges and perform actions as the logged-in user. An attacker with query-level permissions can execute arbitrary JavaScript in the browsers of all users who view the query list, potentially leading to full platform compromise if an administrator executes the payload.
Recommendations Restrict query-level permissions to trusted users. Monitor the query list for suspicious payloads. Review osctrl user accounts for unauthorized administrators.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-28280
GHSA-4RV8-5CMM-2R22
GO-2026-4576
SUSE-SU-2026:1042-1

Affected Products

Osctrl