CVE-2026-18247
DOM-Based Cross-Site Scripting in BlackBerry AtHoc Web Portals
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session.
| CWE | CWE-79 |
| Vendor | blackberry |
| Product | blackberry athoc iws |
| Published | Aug 11, 2026 |
| Last Updated | Aug 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for blackberry blackberry athoc iws
Be the first to know when new unknown vulnerabilities affecting blackberry blackberry athoc iws are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
BlackBerry / BlackBerry AtHoc IWS
0 < 7.21 HF-734
References
Credits
Patrick de Noronha aka Pa13cK of Kabuto Security