Junglewise Threat Intelligence

CVE-2026-81824: PIMBoards stored cross-site scripting via malicious link

CVE-2026-81824 · Severity: medium · CVSS 4.7 · Published 2026-09-08

Executive brief

PIMBoards is a web-based collaboration platform. A stored cross-site scripting (XSS) vulnerability allows an attacker to inject and execute arbitrary JavaScript code in the browsers of users who click a malicious link, potentially enabling session hijacking, credential theft, or unauthorized actions performed on behalf of affected users.

Technical details

This is a stored/reflected cross-site scripting (XSS) vulnerability in PIMBoards that permits arbitrary JavaScript execution within an authenticated user's browser session. The vulnerability is triggered when a user is socially engineered to click on a malicious link containing injected JavaScript payload. No additional preconditions beyond user interaction are required. An attacker can execute arbitrary actions in the victim's session, including stealing session tokens, harvesting sensitive data, or performing unauthorized operations. The attack vector is network-based and relies on social engineering to convince the user to click the link.

Affected products

  • PIMBoards

Timeline

  • 2026-09-08: disclosed

References

Related threats