Junglewise Threat Intelligence

CVE-2026-18247: BlackBerry AtHoc IWS cross-site scripting in web portals

CVE-2026-18247 · Severity: info · Published 2026-08-11

Vendors: Blackberry.

Executive brief

AtHoc IWS is a critical incident management and mass notification system used by enterprises to coordinate emergency communications. A cross-site scripting (XSS) vulnerability in its web portal allows attackers to inject malicious code that executes in users' browsers, potentially enabling session hijacking, credential theft, or unauthorized actions performed on behalf of victims.

Technical details

A reflected or stored cross-site scripting (XSS) vulnerability exists in the web portals of AtHoc IWS versions prior to 7.21 HF-734. The vulnerability allows an attacker to inject arbitrary JavaScript code that executes in the context of a victim's authenticated session, typically requiring user interaction (clicking a malicious link) for reflected XSS or no user action for stored XSS. An attacker can exploit this to steal session tokens, modify portal content, perform actions as the victim, or harvest sensitive incident management data. The vulnerability is fixed in version 7.21 HF-734 and later.

Affected products

  • BlackBerry AtHoc IWS before 7.21 HF-734

Timeline

  • 2026-08-11: disclosed

References