Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-41098

Опубликовано: 09 июн. 2026
Источник: msrc
CVSS3: 8.4
EPSS Низкий

Описание

Azure Stack Edge Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

FAQ

According to the CVSS metric, a successful exploitation could lead to a scope change (S:C). What does this mean for this vulnerability?

An exploited vulnerability can affect resources beyond the security scope managed by the security authority of the vulnerable component. In this case, the vulnerable component and the impacted component are different and managed by different security authorities.

How could an attacker exploit this vulnerability?

An attacker could exploit this vulnerability by uploading a crafted SSL/TLS certificate containing malicious JavaScript in its X.509 Subject or Issuer fields to the Azure Stack Edge Local UI certificate management interface. When an administrator views the certificate details, the script executes in their browser session, allowing the attacker to perform administrative actions and access sensitive configuration or cryptographic material within the Local UI.

Обновления

ПродуктСтатьяОбновление
Azure Stack Edge

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 54%
0.00831
Низкий

8.4 High

CVSS3

Связанные уязвимости

CVSS3: 8.4
nvd
около 2 месяцев назад

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

CVSS3: 8.4
github
около 2 месяцев назад

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.

CVSS3: 8.4
fstec
около 2 месяцев назад

Уязвимость интерфейса управления сертификатами программно-аппаратной платформы Microsoft Azure Stack Edge, позволяющая нарушителю проводить спуфинг атаки

EPSS

Процентиль: 54%
0.00831
Низкий

8.4 High

CVSS3