CVE-2026-2101
High
|8.7Exploit Available
Plain English Summary
AI-powered analysis for quick understanding
An attacker can run malicious scripts in a user's web browser session, potentially stealing sensitive information or hijacking the session. This vulnerability affects specific versions of ENOVIAvpm Web Access and requires the user to click on a specially crafted link sent by the attacker.
Technical Description
A Reflected Cross-site Scripting (XSS) vulnerability affecting ENOVIAvpm Web Access from ENOVIAvpm Version 1 Release 16 through ENOVIAvpm Version 1 Release 19 allows an attacker to execute arbitrary script code in user's browser session.
CVSS Vector Analysis
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredLow
User InteractionRequired
Confidentiality ImpactHigh
Integrity ImpactHigh
Availability ImpactNone
ScopeChanged
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:NExploit Resources
Search for proof-of-concept code and exploit modules
Official References
Est. Bounty
$4,579($1K-$5K)
Vendor Response
Grade APatched in 2 days
Quick Information
Published
Feb 16, 2026
about 2 months ago
Last Modified
Feb 18, 2026
about 2 months ago