{"id":"CVE-2026-12559","title":"A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application","summary":"A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized scri…","severity":"high","cvss":7.3,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/S:N/AU:N/R:U/V:D/RE:M/U:Red","cwe":["CWE-79"],"vendor":"OpenText","product":"Vendor Invoice Management for SAP Solutions","affected":["vendor_invoice_management_for_sap_solutions >= VIM 7.6/20.4 <= 0009","vendor_invoice_management_for_sap_solutions >= VIM 23.4 <= 0004","vendor_invoice_management_for_sap_solutions >= VIM 25.4 <= 0001"],"published":"2026-09-24","updated":"2026-09-24","sourceUpdated":"2026-09-24T20:43:32.537","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12559","references":[{"url":"https://support.opentext.com/csm?id=kb_article_view&sysparm_article=KB0869040","label":"security@opentext.com"},{"url":"https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0869044","label":"security@opentext.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-24T14:51:19.732789Z"},"cvssSource":"cna","ingestedAt":"2026-09-24T15:45:56.637Z","slug":"CVE-2026-12559","body":"## Overview\n\nA Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":40,"depthScoreParts":{"impact":40.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}