PT-2026-40445 · Efw · Efw

CVE-2026-44259

·

Published

2026-05-12

·

Updated

2026-05-13

CVSS v3.1

4.6

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions efw4.X versions prior to 4.08.010
Description The 'previewServlet' serves files using detected MIME types based on file extensions without applying security headers or content sanitization. Files with extensions such as .html, .htm, or .svg are served as 'text/html' or 'image/svg+xml', which allows embedded JavaScript to execute in the user's browser within the application's origin.
Recommendations Update to version 4.08.010.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44259
GHSA-HW67-P3GW-RRMJ

Affected Products

Efw