PT-2026-28634 · Thales · Thales Sentinel Ldk Runtime

·

CVE-2026-3457

·

Published

2026-03-27

·

Updated

2026-09-03

CVSS v3.1

6.8

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:N
Name of the Vulnerable Software and Affected Versions Thales Sentinel LDK Runtime versions prior to 10.22
Description The software contains an Improper Neutralization of Input During Web Page Generation issue, which allows for Stored Cross-site Scripting (XSS). This means that malicious scripts can be injected into web pages viewed by other users. The issue affects the software on Windows systems.
Recommendations Update Thales Sentinel LDK Runtime to version 10.22 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3457

Affected Products

Thales Sentinel Ldk Runtime