Stored XSS Vulnerability in vCluster Platform Affects Loft
CVE-2026-42457
9CRITICAL
What is CVE-2026-42457?
The vCluster Platform from Loft is susceptible to a Stored XSS security issue that arises from improper handling of the name field in a template reference. This vulnerability allows an attacker with namespace creation permissions to inject and execute arbitrary JavaScript code within the platform’s browser context. This can enable malicious users to potentially escalate their privileges by creating unauthorized Global-Admin accounts, compromising security controls in place. Update to versions 4.4.3, 4.5.5, 4.6.2, 4.7.1, or 4.8.0 to remediate this risk.
Affected Version(s)
loft < 4.4.3 < 4.4.3
loft >=4.5.0-alpha.0 , < 4.5.5 < 4.5.0-alpha.0 , 4.5.5
loft >= 4.6.0-alpha.1, < 4.6.2 < 4.6.0-alpha.1, 4.6.2
