Junglewise Threat Intelligence

CVE-2026-14466: Stormshield Network Security stored XSS in web administration panel

CVE-2026-14466 · Severity: medium · CVSS 4.3 · Published 2026-09-04

Technologies: Stormshield Network Security. Vendors: Stormshield.

Executive brief

Stormshield Network Security (SNS) is a network security appliance used to protect corporate networks. A stored cross-site scripting (XSS) vulnerability in the web administration panel allows authenticated administrators to inject malicious scripts that persist and execute in the browser of other administrators who view the affected content, potentially leading to unauthorized actions or data theft.

Technical details

This is a stored XSS vulnerability in the Stormshield SNS web administration panel. The vulnerability exists in the group comments functionality of the webservices administration interface, where an SNS administrator with appropriate permissions can inject malicious JavaScript code. The injected script persists in the system and executes when other administrators view the affected group comments. Exploitation requires administrative privileges and user interaction (another administrator must view the malicious comment), and the attack is limited to the adjacent network (AV:A). No workarounds are available; patches are available in SNS 5.1.0, 5.0.7, and 4.8.17.

Affected products

  • Stormshield Network Security 4.8.0 to 4.8.16, 5.0.0 to 5.0.6

Timeline

  • 2025-12-17: disclosed: Vulnerability discovered
  • 2026-03-04: advisory: Initial advisory release (v1)
  • 2026-09-04: advisory: Advisory updated and disclosed (v2)
  • 2026-09-04: patched: Patches available: SNS 5.1.0, SNS 5.0.7, SNS 4.8.17

References

Related threats