Stored Cross-Site Scripting Vulnerability in Verba Management System
CVE-2026-21730

5.3MEDIUM

Key Information:

Vendor

Verint

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-21730?

The Verba Management System contains a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthorized user attempts to log in with an invalid username and password, the provided username is logged by the system. Because of inadequate input sanitization, this exposes a vector for an attacker to inject a harmful XSS payload into the username field. If the administrator then accesses the log viewer, the malicious payload is executed within the context of the admin's browser, potentially compromising the security of the application and its users.

Affected Version(s)

Verba 0 < 10.0.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jan Czerlunczakiewicz (STM Cyber)
.