PT-2026-95587 · Red Hat · Exploit Intelligence+5

CVE-2026-93432

·

Published

2026-09-18

·

Updated

2026-09-27

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Quarkus Qute (affected versions not specified)
Description A flaw in the Quarkus Qute template engine occurs when the {#eval} section helper processes a sub-template and fails to pass the parent template's content type information. This failure bypasses standard escaping mechanisms, allowing untrusted data to be output as raw, unescaped text. This can lead to Cross-Site Scripting (XSS), where arbitrary code is executed in a user's browser, and JSON Injection, which allows for data manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-93432

Affected Products

Exploit Intelligence
Red Hat Build Of Keycloak
Red Hat Fuse 7
Red Hat Build Of Apache Camel 4 For Quarkus 3
Red Hat Build Of Apicurio Registry 3
Red Hat Build Of Quarkus