Stored Cross-Site Scripting Vulnerability in Ellucian Banner Self-Service
CVE-2026-47106

5.1MEDIUM

Key Information:

Vendor

Ellucian

Vendor
CVE Published:
9 June 2026

What is CVE-2026-47106?

Ellucian Banner Self-Service prior to the April 2025 T2 release has a vulnerability that allows authenticated users to inject malicious scripts into critical faculty and course fields. Due to missing HTML encoding during DOM insertion, these manipulations can exploit the getFacultyMeetingTimes API endpoint, leading to unsanitized data exposure. As a result, any user accessing the affected course meeting times may unknowingly execute harmful JavaScript within their browser, jeopardizing data integrity and user security.

Affected Version(s)

Banner Self-Service 0

Banner Self-Service 0

Banner Self-Service 9.41

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Abdullah M. Alotaibi
.