CVE-2026-40212 PUBLISHED

Assigner: mitre
Reserved: 10.04.2026 Published: 10.04.2026 Updated: 10.04.2026

OpenStack Skyline before 5.0.1, 6.0.0, and 7.0.0 has a DOM-based Cross-Site Scripting (XSS) vulnerability in the console because document.write is used unsafely, which is relevant in scenarios where administrators use the console web interface to view instance console logs.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
CVSS Score: 5.4

Product Status

Vendor OpenStack
Product Skyline
Versions Default: unaffected
  • affected from 0 to 5.0.1 (excl.)
  • Version 6.0.0 is affected
  • Version 7.0.0 is affected

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') CWE