AUGUST 21, 2026
Live Feed
Back to database
Case File

CVE-2026-8309

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The Access Control System (GKS) from Armiya Information Technologies is vulnerable to reflected cross-site scripting (XSS) due to improper input neutralization during web page generation. This flaw could allow attackers to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or session hijacking. Organizations using GKS versions prior to 2 should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-8309
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%

Original NVD Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This issue affects Access Control System (GKS): before Version 2.