Junglewise Threat Intelligence

CVE-2026-12559: OpenText Vendor Invoice Management stored cross-site scripting

CVE-2026-12559 · Severity: info · Published 2026-09-24

Executive brief

OpenText Vendor Invoice Management for SAP Solutions contains a stored cross-site scripting (XSS) vulnerability that could allow an attacker to inject and execute malicious scripts in users' browsers. This could compromise the confidentiality and integrity of sensitive invoice data and financial information processed through the application. Exploitation requires specific conditions but could lead to unauthorized access to or manipulation of vendor invoice records.

Technical details

A stored XSS vulnerability exists in the Capture Validation component of OpenText Vendor Invoice Management for SAP Solutions, allowing persistent injection of unauthorized script content. The vulnerability requires certain preconditions to trigger but persists in the application's data store, affecting any user who views the malicious content. The attack vector and specific attack preconditions are not fully detailed in available references.

Affected products

  • OpenText Vendor Invoice Management for SAP Solutions

Timeline

  • 2026-09-24: disclosed

References