Junglewise Threat Intelligence

CVE-2026-8152: Unblu Spark DOM-based XSS via redirectOnFailure parameter

CVE-2026-8152 · Severity: info · CVSS 9.3 · Published 2026-07-22

Technologies: Unblu Spark.

Executive brief

Unblu Spark, a platform for customer engagement and collaboration, contains a security flaw in how it handles web redirects. An attacker can trick a user into clicking a malicious link that executes unauthorized code within their browser session. In certain configurations where Unblu is deeply integrated into a company's main website, this could allow an attacker to steal sensitive session cookies, access private user data, or perform actions on behalf of the user across the entire host application.

Technical details

An open redirect vulnerability exists in Unblu Spark due to insufficient validation of the 'redirectOnFailure' URL parameter. This parameter is not passed through the standard redirect filter, allowing an attacker to use the 'javascript:' scheme to execute arbitrary code in the victim's browser (DOM-based XSS). The impact is significantly escalated when 'com.unblu.identifier.siteEmbeddedSetup' is set to true, as the application then shares the same origin as the host application. In this configuration, the injected script can access the host application's cookies, DOM, and same-origin APIs. The vulnerability is fixed in version 8.36.1-hotfix.0 and 8.37.0.

Affected products

  • Unblu Spark 8.36.1 and all earlier versions

Timeline

  • 2026-07-22: advisory
  • 2026-07-22: disclosed

References