JavaScript Injection Flaw in OPEXUS eCASE Audit
CVE-2026-22233

4.8MEDIUM

Key Information:

Vendor

Opexus

Vendor
CVE Published:
8 January 2026

What is CVE-2026-22233?

OPEXUS eCASE Audit is susceptible to a security flaw that allows authenticated users to inject JavaScript code into the 'Estimated Staff Hours' field as a comment. This malicious script is executed when other users access the Project Cost tab, potentially leading to unauthorized actions or data exposure. It is crucial for users to update to version 11.14.2.0 or later to mitigate this risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

eCASE Audit 11.4.0 < 11.14.2.0

eCASE Audit 11.14.2.0

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aaron M. Ramirez, Son Nguyen, Wesley Cuffee, United States Department of Justice
.