SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-69149

MEDIUM · CVSS 6.1 EPSS 0.21% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-03 · Last synced 2026-09-02

CyberRota Analysis

AI-Generated

A Cross-Site Scripting (XSS) vulnerability in the DOM emulation dependency of @angular/platform-server affects versions prior to 20.3.27, 21.2.19, and 22.0.7, allowing attackers to inject malicious scripts through fallback raw-content elements like <iframe> and <noscript>. This could lead to unauthorized access or manipulation of user data. Developers and organizations using affected Angular versions should prioritize updating to the patched releases to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-69149
Severity
MEDIUM
CVSS
6.1
EPSS
0.21%
Java

Original NVD Description

Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 20.3.27, 21.2.19, and 22.0.7, a Cross-Site Scripting (XSS) vulnerability exists in @angular/platform-server's DOM emulation dependency (domino) when serializing the content of fallback raw-content elements (<iframe>, <noembed>, <noframes>, and <noscript>). This issue is fixed in versions 20.3.27, 21.2.19, and 22.0.7.

Related CVEs

Other vulnerabilities affecting the same vendor(s)