🔐 CVE Alert

CVE-2026-14466

MEDIUM 4.3

Possible XSS in the SNS web administration panel

CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th

It’s possible to run a stored XSS in Stormshield’s web administration panel. To exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.

CWE CWE-79
Vendor stormshield
Product stormshield network security
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for stormshield stormshield network security

Be the first to know when new medium vulnerabilities affecting stormshield stormshield network security are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Stormshield / Stormshield Network Security
4.8.0 ≤ 4.8.16 5.0.0 ≤ 5.0.6

References

NVD ↗ CVE.org ↗ EPSS Data ↗
advisories.stormshield.eu: https://advisories.stormshield.eu/2026-006

Credits

We acknowledge the researcher Supr4s for discovering this vulnerability.