# CVE-2026-79418

## Summary

- **CVE ID:** CVE-2026-79418
- **Severity:** HIGH
- **CVSS Score:** 8.7 (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N)
- **CWE:** N/A
- **Published:** Sep 4, 2026
- **Last Modified:** Sep 15, 2026

## Description

EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.

## Affected Products

- n/a — n/a (n/a)

## References

- [CNA](https://drive.google.com/file/d/1mp-uS-tAthH9FAObfx1D3lOM7IIjRsmE/view?usp=sharing)
- [CNA](https://emxtecnologia.com.br/gestao-x-business-suite/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.3

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-18._