PT-2026-50797 · Unknown · Hashgraph Guardian

·

CVE-2026-22674

·

Published

2026-06-18

·

Updated

2026-06-23

CVSS v3.1

4.8

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Hashgraph Guardian versions prior to 3.5.0 commit ba8c566
Description A stored cross-site scripting issue exists where authenticated users with the STANDARD REGISTRY role can inject malicious scripts. This occurs by submitting a crafted companyName value through the branding configuration API endpoint. The flaw is caused by an unsanitized innerHTML assignment in the branding service, which allows arbitrary JavaScript to execute in the browser of every authenticated user upon every page load.
Recommendations Update to the version containing commit ba8c566. Restrict the use of the companyName variable in the branding configuration API endpoint until the update is applied.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-22674

Affected Products

Hashgraph Guardian