Executive brief
Verint Verba, a platform used for recording and managing business communications, contains a security flaw in its login logging system. An unauthorized attacker can submit a malicious username that, when viewed by a system administrator in the application logs, allows the attacker to execute commands in the administrator's browser. This could lead to unauthorized access to sensitive communication data or administrative control over the platform.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Verint Verba due to insufficient input sanitization of the username field during failed login attempts. When an unauthenticated remote attacker provides a malicious XSS payload as a username, the application records this value verbatim into its internal logs. The payload is subsequently executed in the security context of an administrator's session when they view the application's log viewer. This vulnerability is tracked as CVE-2026-21730 and was addressed in version 10.0.6.
Affected products
- Verint Verba (Collaboration Compliance and Quality Management Platform) All versions before 10.0.6
Timeline
- 2026-05-14: advisory: Initial advisory published by CERT.PL
- 2026-05-14: disclosed
- 2026-05-14: patched: Fixed in version 10.0.6