{"id":"CVE-2026-14466","title":"It’s possible to run a stored XSS in Stormshield’s web administration panel.\n\n\n\nTo exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices a…","summary":"It’s possible to run a stored XSS in Stormshield’s web administration panel.\n\n\n\nTo exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices a…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:H/UI:R/S:U/C:H/I:N/A:N","cwe":["CWE-79"],"published":"2026-09-04","updated":"2026-09-08","sourceUpdated":"2026-09-08T14:03:48.663","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-14466","references":[{"url":"https://advisories.stormshield.eu/2026-006","label":"cert@airbus.com"}],"tags":["nvd"],"epss":0.0016,"epssPercentile":0.05628,"ingestedAt":"2026-09-08T15:33:26.961Z","slug":"CVE-2026-14466","body":"## Overview\n\nIt’s possible to run a stored XSS in Stormshield’s web administration panel.\n\n\n\nTo exploit this vulnerability, a SNS administrator with appropriate permissions must inject  some malicious script in a group’s comments in the webservices administration interface.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}