Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/NullByte8080/CVE-2026-36226 |
|
Fri, 22 May 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in Advantech WebAccess/SCADA Decryption Field Enables Sensitive Data Disclosure | |
| First Time appeared |
Advantech
Advantech webaccess/scada |
|
| Vendors & Products |
Advantech
Advantech webaccess/scada |
Fri, 22 May 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Fri, 22 May 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-22T17:33:38.680Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36226
Updated: 2026-05-22T17:33:34.508Z
Status : Awaiting Analysis
Published: 2026-05-22T17:16:46.813
Modified: 2026-06-17T10:41:04.290
Link: CVE-2026-36226
No data.
OpenCVE Enrichment
Updated: 2026-05-22T20:00:13Z