CVE-2026-2680 PUBLISHED

Multiple vulnerabilities in A3factura software

Assigner: INCIBE
Reserved: 18.02.2026 Published: 26.02.2026 Updated: 26.02.2026

Reflected Cross-Site Scripting (XSS) on the A3factura web platform, in parameter 'customerVATNumber', in 'a3factura-app.wolterskluwer.es/#/incomes/salesDeliveryNotes' endpoint, which could allow an attacker to execute arbitrary code in the victim's browser.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
CVSS Score: 4.8

Product Status

Vendor A3factura
Product A3factura
Versions Default: unaffected
  • Version 4.111.2-rev.1 is affected

Solutions

The fix has been deployed in production in version 4.114.0-rev.6, released on 17/02/2026.

Credits

  • David Padilla Alvarado finder

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE