Junglewise Threat Intelligence

CVE-2026-12812: Radware Cyber Controller HTML injection in HTML Report Generation

CVE-2026-12812 · Severity: low · CVSS 3.5 · Published 2026-06-21

Executive brief

Radware Cyber Controller, a centralized management solution for security and network services, is vulnerable to an HTML injection flaw in its report generation feature. An attacker could use this to inject malicious content into reports, potentially misleading administrators or facilitating further attacks when the reports are viewed. While the impact is considered low, the exploit has been publicly disclosed and the vendor has not yet provided a fix.

Technical details

A vulnerability classified as HTML injection (CWE-74/CWE-80) exists in the HTML Report Generation component of Radware Cyber Controller versions up to 10.11.0. The flaw allows a remote attacker with low-level privileges to manipulate input that is subsequently rendered in generated HTML reports without proper neutralization. Exploitation requires the victim to view the malicious report (user interaction). While the CVSS score is low (3.5), an exploit has been publicly disclosed. As of the advisory date, the vendor has not responded to the disclosure or released a patch.

Affected products

  • Radware Cyber Controller up to 10.11.0

Timeline

  • 2026-06-21: disclosed: Public disclosure of the exploit
  • 2026-06-21: advisory: CVE-2026-12812 published

References