Junglewise Threat Intelligence

CVE-2026-2342: OceanicSoft ValeApp stored XSS

CVE-2026-2342 · Severity: critical · CVSS 9.3 · Published 2026-07-09

Executive brief

OceanicSoft ValeApp contains a security flaw that allows attackers to inject malicious scripts into the application. When other users or administrators view the affected pages, these scripts can execute automatically, potentially leading to the theft of sensitive session information or unauthorized actions performed on behalf of the user. This issue remains unpatched as the vendor has not responded to security notifications.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in OceanicSoft ValeApp through version 09072026. The application fails to properly sanitize user-supplied input before storing it and rendering it on web pages (CWE-79). An unauthenticated remote attacker can exploit this by submitting malicious JavaScript, which is then executed in the context of any user who views the compromised content. This can lead to session hijacking, credential theft, or unauthorized data modification. As of the disclosure date, the vendor has not provided a patch or response.

Affected products

  • OceanicSoft Informatics Systems Ltd. ValeApp through 09072026

Timeline

  • 2026-07-09: disclosed: Public disclosure via NVD and TR-CERT
  • 2026-07-09: advisory

References