Junglewise Threat Intelligence

CVE-2026-7380: Armiya Information Technologies GKS XSS in HTML attributes

CVE-2026-7380 · Severity: medium · CVSS 6.1 · Published 2026-07-07

Technologies: Armiya Information Technologies Ltd. Co. Access Control System (GKS). Vendors: Armiya Information Technologies Ltd. Co..

Executive brief

Armiya Information Technologies' Access Control System (GKS), which manages physical security and entry permissions, is vulnerable to a web-based security flaw. An attacker could trick a user into clicking a malicious link, allowing the attacker to execute unauthorized scripts in the user's browser. This could lead to the theft of login sessions or the performance of unauthorized actions within the security management interface.

Technical details

A basic Cross-Site Scripting (XSS) vulnerability exists in the Armiya Information Technologies Access Control System (GKS) due to improper neutralization of script-related HTML tags. The flaw specifically allows for XSS targeting HTML attributes. This is a network-reachable vulnerability that requires no prior authentication but does require user interaction (UI:R), such as a victim clicking a crafted link. Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized configuration changes. The issue is addressed in Version 2 and later.

Affected products

  • Armiya Information Technologies Ltd. Co. Access Control System (GKS) before Version 2

Timeline

  • 2026-07-07: disclosed
  • 2026-07-07: advisory

References

Related threats