Stored XSS Vulnerability in vCluster Platform Affects Loft
CVE-2026-42457

9CRITICAL

Key Information:

Vendor

Loft-sh

Status
Vendor
CVE Published:
14 May 2026

What is CVE-2026-42457?

The vCluster Platform from Loft is susceptible to a Stored XSS security issue that arises from improper handling of the name field in a template reference. This vulnerability allows an attacker with namespace creation permissions to inject and execute arbitrary JavaScript code within the platform’s browser context. This can enable malicious users to potentially escalate their privileges by creating unauthorized Global-Admin accounts, compromising security controls in place. Update to versions 4.4.3, 4.5.5, 4.6.2, 4.7.1, or 4.8.0 to remediate this risk.

Affected Version(s)

loft < 4.4.3 < 4.4.3

loft >=4.5.0-alpha.0 , < 4.5.5 < 4.5.0-alpha.0 , 4.5.5

loft >= 4.6.0-alpha.1, < 4.6.2 < 4.6.0-alpha.1, 4.6.2

References

CVSS V3.1

Score:
9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.