PT-2026-47873 · Microsoft · Azure Stack Edge

·

CVE-2026-41098

·

Published

2026-06-09

·

Updated

2026-06-09

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Azure Stack Edge (affected versions not specified)
Description Improper neutralization of input during web page generation in the certificate management interface allows an authorized attacker to perform cross-site scripting (XSS), which is a technique where malicious scripts are injected into trusted websites. This can enable the attacker to conduct spoofing attacks over a network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08347
CVE-2026-41098

Affected Products

Azure Stack Edge