Junglewise Threat Intelligence

CVE-2026-50040: StoneFly Storage Concentrator reflected XSS in 404 error pages

CVE-2026-50040 · Severity: medium · CVSS 6.1 · Published 2026-06-30

Technologies: StoneFly Storage Concentrator, StoneFly Storage Concentrator Virtual Machine. Vendors: StoneFly.

Executive brief

StoneFly Storage Concentrator, a solution used for managing enterprise data storage, is vulnerable to a security flaw where it fails to properly clean information displayed on error pages. An attacker could trick a legitimate user into clicking a malicious link, allowing the attacker to run unauthorized scripts in the user's browser. This could lead to the theft of login sessions, unauthorized data access, or the performance of actions on the user's behalf within the storage management system.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in StoneFly Storage Concentrator (SC) and Storage Concentrator Virtual Machine (SCVM) prior to version 8.0.4.22. The vulnerability is located in the handling of 404 error pages, where the application echoes back unsanitized user-supplied content from the URL. An unauthenticated remote attacker can exploit this by crafting a malicious URL and enticing an authenticated user to visit it. Successful exploitation allows the execution of arbitrary JavaScript in the context of the victim's browser session, potentially leading to session cookie theft or unauthorized application actions. StoneFly recommends upgrading to version 8.0.4.29 or later to remediate this and other related vulnerabilities.

Affected products

  • StoneFly Storage Concentrator < 8.0.4.22
  • StoneFly Storage Concentrator Virtual Machine < 8.0.4.22

Timeline

  • 2026-06-30: advisory: CISA and NVD published the advisory.
  • 2026-06-30: disclosed

References

Related threats