CVE-2026-3278 PUBLISHED

XSS Vulnerability discovered in OpenText™ ZENworks Service Desk.

Assigner: OpenText
Reserved: 26.02.2026 Published: 18.03.2026 Updated: 18.03.2026

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ ZENworks Service Desk allows Cross-Site Scripting (XSS). The vulnerability could allow an attacker to execute arbitrary JavaScript leading to unauthorized actions on behalf of the user.This issue affects ZENworks Service Desk: 25.2, 25.3.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:N/SC:L/SI:L/SA:N/S:N/AU:Y/R:U/V:D/RE:M/U:Amber
CVSS Score: 7.4

Product Status

Vendor OpenText™
Product ZENworks Service Desk
Versions Default: unaffected
  • Version 25.2 is affected
  • Version 25.3 is affected

Solutions

https://portal.microfocus.com/s/article/KM000045873?language=en_US

References

Problem Types

  • CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') CWE

Impacts

  • CAPEC-63 Cross-Site Scripting (XSS)