SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79418

HIGH · CVSS 8.7 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

EMX Tecnologia Gestao X versions up to 8.4 are vulnerable to a Stored Cross-Site Scripting (XSS) flaw in the Help Chat feature, which allows authenticated attackers to inject and execute arbitrary JavaScript in the browsers of other authenticated users. This vulnerability can lead to severe consequences, including session hijacking and account takeover. Organizations using this software should prioritize remediation to protect against potential exploitation by malicious actors.

CVE
CVE-2026-79418
Severity
HIGH
CVSS
8.7
EPSS
0.26%
Java

Original NVD Description

EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.