CVE-2026-41468
Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser compromise. Network-adjacent attackers can deliver the complete injection and escape chain via MITM in plaintext HTTP deployments without active user interaction.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.3
- CVSS vector
- CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
- EPSS probability
- 0.39%
- CWE
- CWE-1104
- Published
- 2026-04-22
- Last modified
- 2026-04-22
Affected products
- Beghelli SicuroWeb (Sicuro24)
Weakness type
Related vulnerabilities
- CVE-2026-21753 — HCL Hive is affected by multiple security vulnerabilities.
- CVE-2026-12554 — HP Easy Start for macOS - Security Update
- CVE-2026-21752 — HCL Hive is affected by a use of vulnerable third-party components
- CVE-2026-66788 — Lighthouse: dockerfile build stages use end-of-life fedora 40 referenced by mutable tag
- CVE-2026-11325 — cloudflare/pages-action is deprecated — migration required by September 18th, 2026
- CVE-2026-16634 — TOML::XS versions before 0.06 for Perl bundle an unsupported and vulnerable version of tomlc99
- CVE-2026-56580 — HCL MyCloud was affected by Using Components with Known Vulnerability
- CVE-2026-3031 — Image::EPEG versions through 0.15 for Perl embeds an unsupported version of the Epeg library