CVE-2026-8152 PUBLISHED

Unblu Spark Open Redirect leading to DOM-Based XSS

Assigner: NCSC.ch
Reserved: 08.05.2026 Published: 22.07.2026 Updated: 22.07.2026

Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack.

When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript injected through this vulnerability therefore executes with full access to the host application's cookies, DOM, and same-origin APIs — an attacker can reach all resources of the host application, not just Unblu's. This expanded blast radius is the reason on-premises deployments using this configuration are rated CRITICAL.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N
CVSS Score: 9.3

On-premises deployment (same site)

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 7

Cloud deployment

Product Status

Vendor Unblu inc.
Product Unblu Spark
Versions Default: affected
  • affected from 0 to 8.36.1 (incl.)
  • Version 8.36.1-hotfix.0 is unaffected
  • Version 8.37.0 is unaffected

Workarounds

If you cannot upgrade immediately, either of the following measures prevents exploitation:

  • Enable the built-in Content Security Policy by setting com.unblu.contentsecuritypolicy.mode=on. The CSP blocks the injected JavaScript from executing and prevents the exploit from succeeding. Note: this protection is only effective on Unblu Spark 7.56.2 or later in the 7.x series and 8.19.1 or later in the 8.x series, where unsafe-inline was removed from the script source policy. Earlier versions ship a CSP that still permits unsafe-inline and are not protected by this workaround.
  • Configure a WAF rule to block requests that carry a malicious payload in the redirectOnFailure parameter (in particular, values containing a javascript: scheme or obfuscated variants such as java%0ascript:).

Solutions

In the fix versions listed above, Unblu Spark validates all user-supplied redirects through the same redirect filter.

After upgrading, please review your redirect filter configuration. The defaults restrict redirects to the current origin (document.location.origin).

Credits

  • Kenan Karalioglu (chef_shell) via YesWeHack finder

References

Problem Types

  • CWE-601 URL Redirection to Untrusted Site ('Open Redirect') CWE
  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE

Impacts

  • CAPEC-588 — DOM-Based XSS