---
id: CVE-2026-85406
title: A vulnerability has been found in Eleveo Quality Management 9.7.0
summary: >-
  A vulnerability has been found in Eleveo Quality Management 9.7.0. This
  vulnerability affects unknown code of the component Conversation Review. The
  manipulation leads to cross site scripting. Remote exploitation of the attack
  is possibl…
severity: low
cvss: 3.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
  - CWE-94
vendor: Eleveo
product: Quality Management
affected:
  - quality_management 9.7.0
published: '2026-09-04'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T15:18:51.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85406'
references:
  - url: >-
      https://drive.google.com/file/d/12AssEiP2iGOM9UwkXM39TwGoPxOexHX2/view?usp=sharing
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-85406'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/894900'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/398556'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/398556/cti'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T14:35:26.785879Z'
epss: 0.00331
epssPercentile: 0.23528
ingestedAt: '2026-09-08T15:33:26.959Z'
---

## Overview

A vulnerability has been found in Eleveo Quality Management 9.7.0. This vulnerability affects unknown code of the component Conversation Review. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
