Stored Cross-Site Scripting Vulnerability in T-Systems TAO 2.0
CVE-2026-92976
5.1MEDIUM
What is CVE-2026-92976?
A stored Cross-Site Scripting (XSS) vulnerability exists within the profile management feature of T-Systems’ TAO 2.0 suite. This issue allows an authenticated user to inject harmful HTML or JavaScript into their personal data fields. When another user, including administrative personnel, views the affected profile, the malicious content is displayed without adequate sanitization, paving the way for potential exploitation. Through successful attack vectors, the injected JavaScript could execute in the victim's browser, leading to unauthorized access to session data or execution of actions on behalf of the victim.
Affected Version(s)
TAO 2.0
