Reflected XSS Vulnerability in SNOMED International Snowstorm
CVE-2026-66300

2.3LOW

Key Information:

Status
Vendor
CVE Published:
4 August 2026

What is CVE-2026-66300?

SNOMED International Snowstorm is susceptible to a reflected Cross-Site Scripting (XSS) vulnerability that arises from its 'Web Route' redirection feature. An attacker can exploit this flaw by crafting malicious links designed to execute arbitrary JavaScript within the context of a victim's browser. This risk could lead to unauthorized actions or data exposure, underscoring the importance of timely patching. The vulnerability has been addressed in the releases 10.12.2 and 10.9.3.

Affected Version(s)

Snowstorm 7.0.0 < 10.12.2

Snowstorm 10.12.2

Snowstorm 10.9.3

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Milkovich, CISA
Karl Meister, CISA
.