CVE-2026-36748 Details
Description
RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.
A cross-site scripting (XSS) vulnerability has been identified in Rock RMS versions through 17.7.0. This issue allows for the execution of arbitrary JavaScript in the context of an administrator's browser session, potentially leading to unauthorized privilege escalation. The vulnerability arises from inadequate input sanitization in the Social Media Links feature of user profiles. When an administrator views a profile containing a crafted XSS payload, the payload executes and can escalate the profile owner's privileges to that of an administrator.
To mitigate this vulnerability, disable the Social Media Links feature within user profiles. This can be done by navigating to the Admin Settings, selecting General, and then accessing Person Attributes to uncheck the Active box for each social media type.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 3, 2026CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://raxis.com/blog/cve-2026-36748-xss-in-rock-rms-leads-to-privilege-escalation/ | CISA-ADP | ExploitRemedyTechnical Analysis |
| https://raxis.com/blog/cve-2026-36748-xss-in-rock-rms-leads-to-privilege-escalation/ | [email protected] | ExploitRemedyTechnical Analysis |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| RockRMS | <= 17.7.0 (semver) |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jul 5, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | CVE Modified | CISA-ADP |
| Jun 3, 2026 | New CVE Received | [email protected] |
Volerion