Cross-Site Scripting Vulnerability in Cybozu Garoon
CVE-2026-57279

6MEDIUM

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-57279?

Cybozu Garoon is susceptible to a cross-site scripting vulnerability where an attacker can potentially execute arbitrary scripts in the web browser of a user logged into the application. If successfully exploited, this vulnerability could lead to unauthorized actions being performed within the web environment, compromising user safety and data integrity. It is crucial for users and administrators of Cybozu Garoon to be aware of this vulnerability, assess their exposure, and implement appropriate security measures to mitigate risks.

Affected Version(s)

Cybozu Garoon 6.17.0 <= 6.17.1

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

CVSS V3.0

Score:
6.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.