CVE-2026-18084: Cross-Site Scripting (XSS) in time zone parameter of BlackBerry UEM
Published Jul 28, 2026
·Updated
Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS).
This issue affects UEM: 12.23.0 QF8 or earlier.
Affected Software
1 affected component
BlackBerry BlackBerry UEM Management Console<=12.23.0 QF8
Event History
Jul 28, 2026
CVE Published
via MITRE·04:22 PM
Data Sourced
via MITRE·04:22 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-18084?
CVE-2026-18084 is assigned a risk score of 32, indicating a moderate severity level.
2
What systems are affected by CVE-2026-18084?
CVE-2026-18084 affects BlackBerry UEM Management Console version 12.23.0 QF8 and earlier.
3
How do I fix CVE-2026-18084?
To remediate CVE-2026-18084, update to a version of BlackBerry UEM Management Console later than 12.23.0 QF8.
4
What type of vulnerability is CVE-2026-18084?
CVE-2026-18084 is a Cross-Site Scripting (XSS) vulnerability due to improper input neutralization.
5
What impact does CVE-2026-18084 have?
CVE-2026-18084 can allow an attacker to execute malicious scripts in the context of a user's session, compromising security.