CVE-2026-14466 PUBLISHED

Possible XSS in the SNS web administration panel

Assigner: airbus
Reserved: 02.07.2026 Published: 04.09.2026 Updated: 04.09.2026

It’s possible to run a stored XSS in Stormshield’s web administration panel.

To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
CVSS Score: 4.3

Product Status

Vendor Stormshield
Product Stormshield Network Security
Versions Default: unknown
  • affected from 4.8.0 to 4.8.16 (incl.)
  • affected from 5.0.0 to 5.0.6 (incl.)
  • Version 4.8.17 is unaffected
  • Version 5.0.7 is unaffected
  • Version 5.1.0 is unaffected

Solutions

The following updates will fix this vulnerability:

  • SNS 5.1.0
  • SNS 5.0.7
  • SNS 4.8.17

Credits

  • We acknowledge the researcher Supr4s for discovering this vulnerability. finder

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE