AUGUST 14, 2026
Live Feed
Back to database
Case File

CVE-2026-56858

MEDIUM · CVSS 6.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-14

CyberRota Analysis

AI-Generated

This vulnerability allows attackers to inject arbitrary content through unescaped inputs that prematurely close a '/' character, potentially leading to cross-site scripting (XSS) attacks. Organizations using affected products should prioritize remediation efforts to mitigate the risk of unauthorized data manipulation and exploitation. Security teams should assess their applications for this issue, especially those handling user-generated content or inputs.

CVE
CVE-2026-56858
Severity
MEDIUM
CVSS
6.1
EPSS
0.20%

Original NVD Description

Previously, pathological inputs could close an unescaped '/' early, allowing for attack-controlled data to inject arbitrary content, potentially leading to XSS.