CVE-2026-41468 Details
Description
Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser compromise. Network-adjacent attackers can deliver the complete injection and escape chain via MITM in plaintext HTTP deployments without active user interaction.
A vulnerability in Beghelli Sicuro24's web management interface, SicuroWeb, allows for arbitrary JavaScript execution in operator browser sessions. This issue arises from an AngularJS template injection vulnerability, combined with a known sandbox escape in AngularJS version 1.5.2, which is embedded in the application. The vulnerability enables session hijacking, DOM manipulation, and a persistent compromise of the browser. Network-adjacent attackers can exploit this vulnerability by injecting the necessary payloads into the victim's browser via a Man-in-the-Middle (MITM) attack, taking advantage of unencrypted HTTP communications.
As of now, no patch is available for this vulnerability. However, it is recommended to upgrade AngularJS to version 1.6 or later, deploy a restrictive Content Security Policy, enforce HTTPS with HSTS, sanitize template rendering to prevent user input from being evaluated as code, and segment networks to restrict access to management interfaces.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 22, 2026CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22191-POC.py | [email protected] | ExploitTechnical Description |
| https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22191-SicuroWeb-ATI-chain.txt | [email protected] | BundleTechnical Analysis |
| https://www.beghelli.it | [email protected] | Vendor |
| https://www.boffsec-services.com/posts/sicuroweb-cve-2026-22191/ | [email protected] | BundleExploitRemedyTechnical Analysis |
| https://www.vulncheck.com/advisories/beghelli-sicuro24-sicuroweb-angularjs-sandbox-escape-via-template-injection | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1104 | Use of Unmaintained Third Party Components | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Beghelli SicuroWeb | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | New CVE Received | [email protected] |
Volerion