PT-2026-26064 · Opentext · Opentext Zenworks Service Desk

Published

2026-03-18

·

Updated

2026-03-18

·

CVE-2026-3278

CVSS v4.0

7.4

High

VectorAV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
Name of the Vulnerable Software and Affected Versions OpenText ZENworks Service Desk versions 25.2 through 25.3
Description An improper neutralization of input during web page generation can lead to Cross-Site Scripting (XSS) in OpenText ZENworks Service Desk. This could allow an attacker to execute arbitrary JavaScript, potentially enabling unauthorized actions performed with a user's privileges.
Recommendations Update OpenText ZENworks Service Desk to a version later than 25.3.

Fix

RCE

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-3278

Affected Products

Opentext Zenworks Service Desk