Reflected Cross-Site Scripting in Ellucian Banner Self-Service
CVE-2026-32856

5.1MEDIUM

Key Information:

Vendor

Ellucian

Vendor
CVE Published:
9 June 2026

What is CVE-2026-32856?

Ellucian Banner Self-Service prior to the April T2 release harbors a reflected cross-site scripting vulnerability. This allows unauthenticated attackers to execute arbitrary JavaScript within a user's browser by manipulating the toDateFormat request parameter in the dateConverter endpoint. By crafting a malicious URL aimed at this exposed endpoint, attackers can compromise user sessions, leading to the potential theft of session cookies and other malicious activities executed in the victim's browser context.

Affected Version(s)

Banner Self-Service 0

Banner Self-Service 0

Banner Self-Service 9.23

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdullah M. Alotaibi
Faris Almutairi
VulnCheck
.