PT-2026-45387 · Stormshield · Stormshield Network Security

Published

2026-06-01

·

Updated

2026-06-01

·

CVE-2026-8474

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions Stormshield Network Security versions 4.3.0 through 4.3.41 Stormshield Network Security versions 4.8.0 through 4.8.15 Stormshield Network Security versions 5.0.0 through 5.0.5
Description A reflected Cross-Site Scripting (XSS) issue exists in the login API of the Stormshield SNS appliance. This allows an attacker to execute a script on a victim's machine, potentially leading to the theft of cookies or other sensitive data, and the modification of page behavior, such as redirecting the user to malicious websites.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-8474

Affected Products

Stormshield Network Security