# CVE-2026-24343

## Summary

- **CVE ID:** CVE-2026-24343
- **Severity:** UNKNOWN
- **CVSS Score:** 0
- **CWE:** CWE-643
- **Published:** Feb 10, 2026
- **Last Modified:** Mar 12, 2026

## Description

Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat.

This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0.

Users are recommended to upgrade to version 1.8.0, which fixes the issue.

## Affected Products

- Apache Software Foundation — Apache HertzBeat (1.7.1)

## References

- [CNA](https://lists.apache.org/thread/b2k3jqwffrbo2sy6bl4n0f68kp8bfo1n)
- [CVE](http://www.openwall.com/lists/oss-security/2026/02/09/4)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.73%
- **EPSS Percentile:** 52.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._