PT-2026-48222 · Ellucian · Banner Self-Service

CVE-2026-47106

·

Published

2026-06-09

·

Updated

2026-06-10

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Ellucian Banner Self-Service versions prior to 2025-04-23
Description The course search functionality contains a stored cross-site scripting issue. Authenticated Banner ERP users with write access can inject malicious JavaScript into faculty and course fields due to missing HTML encoding during DOM insertion. The malicious payloads are stored in fields such as displayName, emailAddress, subjectDescription, or courseTitle. These values are then served unsanitized through the 'getFacultyMeetingTimes' API endpoint, leading to arbitrary script execution in the browser of any user viewing the affected course meeting times.
Recommendations Update to the April T2 release (2025-04-23) or a newer version. Restrict write access to faculty and course fields to authorized personnel only to minimize the risk of payload injection.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-47106

Affected Products

Banner Self-Service