CVE-2026-11326
Summary
| CVE | CVE-2026-11326 |
|---|---|
| State | PUBLISHED |
| Assigner | OAI |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-05 02:17:11 UTC |
| Updated | 2026-06-05 18:17:04 UTC |
| Description | OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atlas 1.2025.288.15 narrows access to these APIs to *.chatgpt.com; users should upgrade to 1.2025.288.15 or later. |
Risk And Classification
Primary CVSS: v4.0 6 MEDIUM from 8f4f43ab-ba69-4d92-aa1d-d772184d6fb7
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:L/U:Green
EPSS: 0.000410000 probability, percentile 0.127610000 (date 2026-06-10)
Problem Types: CWE-284 | CWE-284 CWE-284 Improper Access Control
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | 8f4f43ab-ba69-4d92-aa1d-d772184d6fb7 | Secondary | 6 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/... |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighAttack Requirements
NonePrivileges Required
NoneUser Interaction
PassiveConfidentiality
HighIntegrity
NoneAvailability
NoneSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:L/U:Green
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | OpenAI | OpenAI Atlas | affected 1.2025.288.15 custom | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.hacktron.ai/blog/hacking-openai-atlas-browser | 8f4f43ab-ba69-4d92-aa1d-d772184d6fb7 | www.hacktron.ai | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: s1r1us and sudi of hacktron.ai (en)
Additional Advisory Data
Solutions
CNA: Upgrade to OpenAI Atlas 1.2025.288.15 or later.
There are currently no legacy QID mappings associated with this CVE.