Sceawere

Vulnerability Detail

CVE-2026-65937UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

WhatsUp Gold Stored XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8
Creation Date
3h ago
Vendor
Progress Software Corporation
Product
WhatsUp Gold
Attack Type
CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
Vector String
CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

In WhatsUp Gold versions released before 2026.0.2, an authenticated attacker can bypass frontend controls and inject persistent script content.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.0",
  "pubDate": "2026-08-12T16:17:13.527Z",
  "pubdate": "2026-08-12T16:17:13.527Z",
  "executiveSummary": "An authenticated Stored Cross-Site Scripting (XSS) vulnerability has been identified in WhatsUp Gold versions released prior to 2026.0.2. This security flaw allows an authenticated attacker to successfully bypass standard frontend validation controls and persistently inject malicious script content into the application.\nThe primary impact of this vulnerability involves the execution of arbitrary JavaScript within the context of a victim's browser session whenever they view the compromised application interface. This can lead to unauthorized actions performed on behalf of the victim, session hijacking, credential theft, and further compromise of the affected web application environment.\nThe vulnerability affects WhatsUp Gold deployments operating on versions prior to 2026.0.2. Exploitation requires the attacker to possess valid authentication credentials to interact with the application interface and bypass the inadequate frontend security controls. The risk implication is elevated due to the persistent nature of the injected script, which continues to execute for other users accessing the affected components.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient server-side sanitization and validation of user-supplied input combined with weak frontend controls that can be bypassed by an authenticated user. The application fails to properly encode or neutralize malicious payloads before persisting them to the underlying database or storage mechanism.\nThe vulnerable component resides within the frontend and input handling routines of WhatsUp Gold versions prior to 2026.0.2. An authenticated attacker leverages this weakness by submitting crafted input containing malicious script content through interface vectors that fail to enforce robust validation and sanitization policies.\nThe attack flow proceeds as follows: First, the attacker authenticates to the WhatsUp Gold application using valid credentials. Second, the attacker locates an input vector susceptible to persistent injection. Third, the attacker crafts a malicious payload containing JavaScript, bypassing any superficial frontend controls designed to restrict such content. Fourth, the application accepts the input and persists the script content without adequate sanitization. Finally, when another user or administrator navigates to the compromised page or component, the stored script is retrieved from storage and executed within their browser session under the context of their authenticated session.\nPrerequisites for exploitation include network access to the application interface, valid authentication credentials, and low-level user privileges within the system. The payload behavior is characterized by persistent execution in victim browsers, allowing for potential session theft, DOM manipulation, and secondary actions executed with the privileges of the victim."
}
CVE-2026-65937: WhatsUp Gold Stored XSS Vulnerability (HIGH Severity, CVSS: 8.0) - Sceawere