Junglewise Threat Intelligence

CVE-2026-3457: Thales Sentinel LDK Runtime stored XSS on Windows

CVE-2026-3457 · Severity: medium · CVSS 6.8 · Published 2026-03-27

Executive brief

Thales Sentinel LDK Runtime is a software licensing and protection solution used to control access to applications. A stored cross-site scripting (XSS) vulnerability allows an attacker to inject malicious scripts that are permanently stored and executed when other users interact with affected pages, potentially leading to session hijacking, credential theft, or malware distribution.

Technical details

This is a stored XSS vulnerability (CWE-79) caused by improper neutralization of user input during web page generation in Thales Sentinel LDK Runtime on Windows. The vulnerability allows an attacker to inject malicious scripts that are persisted in the application and executed in the browsers of other users who access the affected pages. No authentication or user interaction beyond normal browsing is required to exploit the stored payload. An attacker can achieve arbitrary JavaScript execution in users' browsers, enabling session hijacking, credential harvesting, or client-side malware delivery. The vulnerability affects versions before 10.22, which is expected to contain the fix.

Affected products

  • Thales Sentinel LDK Runtime before 10.22

Timeline

  • 2026-03-27: disclosed

References