CVE-2026-36226
Published May 22, 2026
·Updated
Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component
Affected Software
1 affected component
Advantech WebAccess/SCADA=8.0-2015.08.16
Event History
May 22, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2026-36226?
CVE-2026-36226 has a risk score of 31, indicating a serious cross-site scripting vulnerability.
2
How do I fix CVE-2026-36226?
To fix CVE-2026-36226, sanitize user input in the Create New Project User component to prevent injection.
3
What software is affected by CVE-2026-36226?
CVE-2026-36226 affects Advantech WebAccess/SCADA versions up to 8.0-2015.08.16.
4
What kind of attack can occur due to CVE-2026-36226?
An attacker can exploit CVE-2026-36226 to obtain sensitive information through cross-site scripting.
5
When was CVE-2026-36226 published?
CVE-2026-36226 was published on May 22, 2026.