Possible to run a Cross Site Scripting request on the login API available on Stormshield SNS appliances.
Summary
| CVE | CVE-2026-8474 |
|---|---|
| State | PUBLISHED |
| Assigner | airbus |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-06-01 09:16:21 UTC |
| Updated | 2026-06-01 15:17:42 UTC |
| Description | A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute a reflected XSS attack on the login API available on Stormshield SNS appliance by executing a script on the victim's machine. The risks include the theft of cookies or other sensitive data, as well as the modification of page behavior, for example, by redirecting the victim to malicious websites. |
Risk And Classification
Primary CVSS: v3.1 5.3 MEDIUM from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Problem Types: CWE-79 | CWE-79 CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
| 3.1 | CNA | CVSS | 5.3 | MEDIUM | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
NoneIntegrity
LowAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | StormShield | StormShield Network Security | affected 4.3.0 4.3.41 semver | Not specified |
| CNA | StormShield | StormShield Network Security | affected 4.8.0 4.8.15 semver | Not specified |
| CNA | StormShield | StormShield Network Security | affected 5.0.0 5.0.5 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| advisories.stormshield.eu/2026-003 | [email protected] | advisories.stormshield.eu | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Additional Advisory Data
Solutions
CNA: The following updates fix this vulnerability: * SNS 5.0.6 * SNS 4.8.16 * SNS 4.3.42
There are currently no legacy QID mappings associated with this CVE.