CVE-2026-1243 PUBLISHED

IBM Content Navigator is affected by , a Cross-Site Scripting (XSS) vulnerability

Assigner: ibm
Reserved: 20.01.2026 Published: 02.04.2026 Updated: 02.04.2026

IBM Content Navigator 3.0.15, 3.1.0, and 3.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor IBM
Product Content Navigator
Versions
  • affected from 3.0.15 to 1.11.0 (incl.)
  • Version 3.1.0 is affected
  • Version 3.2.0 is affected

Solutions

Affected VersionsFixes3.0.15ICN 3.0.15 IF0093.1.0ICN 3.1.0 IF008 LA23.2.0ICN 3.2.0 IF004

References