PT-2026-34595 · Unknown · Stig-Manager

Published

2026-04-23

·

Updated

2026-04-23

·

CVE-2026-41200

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions STIG Manager versions 1.5.10 through 1.6.7
Description Reflected Cross-Site Scripting (XSS) occurs in the OIDC authentication error handling code within src/init.js and public/reauth.html. During the OIDC redirect flow, the error and error description query parameters returned by the OIDC provider are written directly to the DOM via innerHTML without HTML escaping. This allows an attacker to execute arbitrary JavaScript in the application origin context by convincing a user to follow a malicious redirect URL. If the user has an active session in another tab, the injected code can communicate with the SharedWorker managing the access token to perform authenticated API requests, such as reading and modifying collection data.
Recommendations Update to version 1.6.8.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41200

Affected Products

Stig-Manager