SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12496

HIGH · CVSS 8.7 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

The Loytec OPC XML-DA server in various products is vulnerable to stored cross-site scripting, allowing unauthenticated remote attackers to inject malicious JavaScript into an administrator's browser through a crafted `User-Agent` header in a specific request. This vulnerability could lead to session hijacking, credential theft, and unauthorized device reconfiguration. Organizations using affected Loytec products should prioritize this issue to mitigate potential security risks.

CVE
CVE-2026-12496
Severity
HIGH
CVSS
8.7
EPSS
0.36%
Java

Original NVD Description

Stored Cross-Site Scripting (CWE-79) in the OPC XML-DA server statistics in Loytec LIP-ME201C, L-INX, L-GATE, L-ROC, L-IOB, L-DALI, L-VIS and L-PAD through 8.4.16 on LINX-A64 allows an unauthenticated remote attacker to execute arbitrary JavaScript in an administrator's browser (session hijacking, credential theft, device reconfiguration) via a crafted `User-Agent` header in a `POST /da` request.