CVE-2026-25735
Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38.5.4, and 39.3.1 have a stored Cross-Site Scripting (XSS) vulnerability in the Identity Name of the WebUI where attacker-controlled input is persisted by the backend and later rendered in the WebUI without proper output encoding. This allows arbitrary JavaScript execution in the context of the WebUI for users who view affected pages, potentially enabling session token theft or unauthorized actions. Versions 35.8.3, 38.5.4, and 39.3.1 fix the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.1
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
- EPSS probability
- 0.29%
- CWE
- CWE-79, CWE-1004
- Published
- 2026-02-25
- Last modified
- 2026-03-12
Affected products
- rucio rucio
- rucio rucio
- rucio rucio
Weakness type
Related vulnerabilities
- CVE-2026-78302 — Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4
- CVE-2026-15889 — Aruba HiSpeed Cache <= 3.0.14 - Authenticated (Contributor+) Stored Cross-Site Scripting via Post Content
- CVE-2026-5399 — Redux Framework <= 4.5.13.1 - Authenticated (Subscriber+) Stored Cross-Site Scripting via Slider Field Value
- CVE-2026-81635 — A cross-site scripting vulnerability exists in SHIRASAGI, which may allow an attacker to execute an...
- CVE-2026-0308 — PAN-OS: Stored Cross-Site Scripting (XSS) Vulnerability in the Web Interface
- CVE-2026-85645 — Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder <= 1.15.46 - Reflected Cross-Site Scripting
- CVE-2026-76562 — Sidebar Manager Light <= 1.18 - Unauthenticated Stored Cross-Site Scripting via 'sbm_description' Parameter
- CVE-2026-4657 — Easy Google Fonts <= 2.0.4 - Authenticated (Author+) Stored Cross-Site Scripting via control_selectors Meta Field