Junglewise Threat Intelligence

CVE-2026-8474: Stormshield Network Security reflected XSS in login API

CVE-2026-8474 · Severity: medium · CVSS 5.3 · Published 2026-06-01

Technologies: Stormshield Network Security. Vendors: Stormshield.

Executive brief

Stormshield Network Security (SNS) is a firewall and security appliance used to protect corporate networks. A vulnerability in its login interface could allow an attacker to execute malicious scripts in a user's browser. This could lead to the theft of login session cookies, unauthorized access to the management console, or the redirection of administrators to fraudulent websites.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in the login API of Stormshield Network Security (SNS) appliances. The flaw is caused by improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by tricking a user into clicking a specially crafted link or visiting a malicious site that interacts with the SNS login API. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking via cookie theft or unauthorized modification of the page's behavior. The vulnerability is fixed in versions 4.3.42, 4.8.16, and 5.0.6.

Affected products

  • Stormshield Stormshield Network Security (SNS) 4.3.0 to 4.3.41, 4.8.0 to 4.8.15, 5.0.0 to 5.0.5

Timeline

  • 2026-01-13: other: Vulnerability discovered
  • 2026-02-19: other: Initial internal advisory release (v1)
  • 2026-05-21: advisory: Public advisory published by Stormshield (v2)
  • 2026-06-01: disclosed: CVE published to NVD

References

Related threats