Junglewise Threat Intelligence

CVE-2026-11878: OpenText Access Manager cross-site scripting

CVE-2026-11878 · Severity: info · CVSS 8.2 · Published 2026-06-24

Executive brief

OpenText Access Manager, a solution used for managing user identities and controlling access to corporate resources, is vulnerable to a security flaw that could allow attackers to inject malicious scripts into web pages. If exploited, this could lead to unauthorized access to user sessions or the theft of sensitive information handled within the management console. This risk primarily affects organizations using versions 5.1 through 5.1.2 of the software.

Technical details

A cross-site scripting (XSS) vulnerability exists in OpenText Access Manager versions 5.1 through 5.1.2. The flaw stems from improper neutralization of user-supplied input during the generation of web pages (CWE-79). An unauthenticated remote attacker can exploit this by sending specially crafted input to the application, potentially leading to the execution of arbitrary JavaScript in the context of a victim's browser session. While the CVSS 4.0 vector indicates high complexity and specific attack requirements, the impact on confidentiality is rated as high. Users are advised to consult OpenText security bulletins for patching information.

Affected products

  • OpenText Access Manager 5.1 through 5.1.2

Timeline

  • 2026-06-24: disclosed
  • 2026-06-24: advisory

References