Junglewise Threat Intelligence

CVE-2026-24662: Fujitsu Musetheque V4 stored XSS in file information page

CVE-2026-24662 · Severity: medium · CVSS 5.4 · Published 2026-05-15

Executive brief

Fujitsu Musetheque V4, a software component used for information disclosure within the IPKNOWLEDGE system, is vulnerable to a security flaw where malicious files can be uploaded to the system. If an administrator views the details of such a file, an attacker's script could run in their browser, potentially allowing the attacker to perform actions on the administrator's behalf or access sensitive session information. This could lead to unauthorized changes or further compromise of the management interface.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Fujitsu Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. The vulnerability is triggered when the application fails to properly neutralize user-supplied input within uploaded files before displaying that information on the administration page. An authenticated attacker with file upload permissions can exploit this by uploading a file containing a malicious payload. When an administrative user views the file's information, the script executes in their security context. This can lead to session hijacking or unauthorized administrative actions. A patch is available in version V4L1 rev2603.1.

Affected products

  • Fujitsu Japan Limited Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier

Timeline

  • 2026-05-15: disclosed
  • 2026-05-15: advisory
  • 2026-05-15: patched: Fixed in V4L1 rev2603.1

References

Related threats