Junglewise Threat Intelligence

CVE-2026-90848: Governikus AusweisApp cross-site scripting in StartPAOSResponse

CVE-2026-90848 · Severity: medium · CVSS 4.3 · Published 2026-09-15

Executive brief

AusweisApp is a German authentication application used to digitally sign documents and access government services. The vulnerability allows an attacker to inject malicious scripts through the ResultMessage parameter, potentially compromising user sessions and enabling credential theft or unauthorized transactions when users visit a malicious website.

Technical details

A cross-site scripting (XSS) vulnerability exists in the StartPAOSResponse Handler component of AusweisApp, triggered by insufficient sanitization of the ResultMessage argument. The vulnerability is remotely exploitable without authentication and requires user interaction (visiting a crafted page). An attacker can inject JavaScript that executes in the victim's browser context, potentially stealing authentication tokens, session cookies, or tricking users into performing unintended actions. The issue is fixed in version 2.5.5; users running versions up to 2.5.4 should upgrade immediately.

Affected products

  • Governikus AusweisApp up to 2.5.4

Timeline

  • 2026-09-15: disclosed
  • 2026-09-15: patched: version 2.5.5 available

References