CVE-2026-41469 Details
Description
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template injection and sandbox escape vulnerabilities present in the same application, the absence of CSP removes the browser-enforced restriction that would otherwise block external script execution, enabling attackers to load arbitrary remote payloads into operator browser sessions.
A vulnerability exists in Beghelli Sicuro24 SicuroWeb due to the lack of a Content Security Policy (CSP), allowing unrestricted loading of external JavaScript from attacker-controlled sources. This vulnerability, when combined with existing template injection and sandbox escape issues in the application, removes browser-enforced restrictions that would typically prevent the execution of external scripts. As a result, attackers can inject arbitrary remote payloads into the browser sessions of operators.
No patch is currently available. However, it is recommended to upgrade or remove AngularJS, deploy a restrictive Content Security Policy, enforce HTTPS with HSTS, sanitize template rendering, and segment networks to restrict access to management interfaces.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Apr 22, 2026CISA-ADP
Assessed Apr 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22191-POC.py | [email protected] | ExploitTechnical Description |
| https://github.com/kmkz/Exploits/blob/master/2026/CVE-2026-22191-SicuroWeb-ATI-chain.txt | [email protected] | BundleTechnical Analysis |
| https://www.beghelli.it | [email protected] | Vendor |
| https://www.boffsec-services.com/posts/sicuroweb-cve-2026-22191/ | [email protected] | BundleExploitRemedyTechnical Analysis |
| https://www.vulncheck.com/advisories/beghelli-sicuro24-sicuroweb-missing-content-security-policy | [email protected] | AdvisoryBundle |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Beghelli SicuroWeb | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 22, 2026 | New CVE Received | [email protected] |
Volerion