CVE-2026-44961

The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users could create usernames that enabled impersonation or stored XSS attacks. Proper validation has been added where it was missing.
CVSS

No CVSS.

References
Configurations

No configuration.

History

No history.

Information

Published : 2026-06-23 17:17

Updated : 2026-06-25 19:52


NVD link : CVE-2026-44961

Mitre link : CVE-2026-44961

CVE.ORG link : CVE-2026-44961


JSON object : View

Products Affected

No product.

CWE
CWE-287

Improper Authentication