Junglewise Threat Intelligence

CVE-2026-41031: Vinna Process Monitor Stored XSS in Media import

CVE-2026-41031 · Severity: high · CVSS 8.7 · Published 2026-06-09

Executive brief

Vinna Process Monitor, a tool used for monitoring industrial or business processes, contains a security flaw in its media import feature. An attacker with basic user access can upload a malicious file that, when viewed by an administrator, steals their login credentials. This could allow an attacker to take full control of the monitoring system, potentially disrupting operations or accessing sensitive process data.

Technical details

A Stored Cross-Site Scripting (XSS) vulnerability exists in the Media import functionality of Vinna Process Monitor. The root cause is improper neutralization of user-supplied input (CWE-79) during file uploads. An authenticated attacker with low privileges can upload a malicious HTML file containing JavaScript. When an administrative user interacts with the uploaded content or follows a link to it, the script executes in the context of the admin's session, exfiltrating Bearer tokens from browser storage to the attacker. This allows for full session hijacking and administrative access. A fix is available in version 4.0.7, with a patch for the 3.1.x branch expected in late 2026.

Affected products

  • Vinna Process Monitor 3.1.0 - 3.1.4, 4.0.0 - 4.0.6

Timeline

  • 2026-06-09: disclosed: Initial discovery and advisory publication
  • 2026-06-09: advisory
  • 2026-06-09: patched: Version 4.0.7 released with fix

References