CVE-2026-8474: Possible to run a Cross Site Scripting request on the login API available on Stormshield SNS appliances.
A vulnerability was discovered on Stormshield Network Security
4.3.0 to 4.3.41, 4.8.0 to 4.8.15, 5.0.0 to 5.0.5
It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page behavior, for example, by redirecting the victim to malicious websites.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 4.3.41 - Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 4.8.15 - Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 5.0.5 - Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 4.3.42 - Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 4.8.16 - Upgrade
Upgrade
Stormshield Network Security (SNS)to a version that resolves this vulnerability.Fixed in 5.0.6
Event History
Frequently Asked Questions
What is the severity of CVE-2026-8474?
The severity of CVE-2026-8474 is classified as medium with a score of 5.3.
How do I fix CVE-2026-8474?
To fix CVE-2026-8474, update to SNS version 5.0.6, 4.8.16, or 4.3.42.
What type of vulnerability is CVE-2026-8474?
CVE-2026-8474 is a reflected Cross Site Scripting (XSS) vulnerability.
What could be the consequences of CVE-2026-8474?
The consequences of CVE-2026-8474 could include the theft of sensitive information from the victim's machine.
Which Stormshield versions are impacted by CVE-2026-8474?
CVE-2026-8474 impacts Stormshield versions 4.3.0 to 4.3.41, 4.8.0 to 4.8.15, and 5.0.0 to 5.0.5.