CVE-2026-33402 Details
Description
Sakai is a Collaboration and Learning Environment (CLE). In versions 23.0 through 23.4 and 25.0 through 25.1, group titles and description can contain cross-site scripting scripts. The patch is included in releases 25.2 and 23.5. As a workaround, one can check the SAKAI_SITE_GROUP table for titles and descriptions that contain this info.
A cross-site scripting (XSS) vulnerability has been identified in Sakai versions 23.0 through 23.4 and 25.0 through 25.1. The issue arises in the group management feature, where group titles and descriptions can be manipulated to include XSS payloads. This vulnerability has been addressed in Sakai releases 25.2 and 23.5. As a temporary measure, users can inspect the SAKAI_SITE_GROUP table for any titles or descriptions that may contain XSS scripts.
Users can update to Sakai versions 25.2 or 23.5, where this vulnerability has been patched. For those unable to update immediately, a workaround involves checking the SAKAI_SITE_GROUP table for titles and descriptions that contain XSS payloads.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/sakaiproject/sakai/security/advisories/GHSA-6g62-3898-hpvm | [email protected] | Vendor Advisory |
| https://sakaiproject.atlassian.net/browse/SAK-52311 | [email protected] | Permissions Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| sakailms sakai | >= 23.0, < 23.5 >= 25.0, < 25.2 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | Initial Analysis | [email protected] |
| Mar 26, 2026 | New CVE Received | [email protected] |