September 7, 2026

CVE Watchtower


← Back to CVE List

CVE-2026-23926NVD

Vulnerability Summary

An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator widget. This can allow the attacker to perform unauthorized actions depending on which user opens the tooltip.
Severity Level
UNKNOWN
Published Date
May 6, 2026
Last Modified
May 7, 2026
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
0.07%Probability
Root Weakness (CWE)
N/A