PT-2026-46878 · Openai · Openai Atlas

CVE-2026-11326

·

Published

2026-06-05

·

Updated

2026-06-05

CVSS v4.0

6.0

Medium

VectorAV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:N/R:X/V:D/RE:L/U:Green
Name of the Vulnerable Software and Affected Versions OpenAI Atlas versions prior to 1.2025.288.15
Description Privileged browser APIs were exposed to web content on *.openai.com origins. A cross-site scripting (XSS) flaw in forum.openai.com could be leveraged to access these functions, enabling an attacker to retrieve browser history information and open or close tabs.
Recommendations Upgrade to version 1.2025.288.15 or later.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-11326

Affected Products

Openai Atlas