CVE-2026-50040 Details
Description
Storage Concentrator (SC & SCVM) is vulnerable to reflected cross-site scripting due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim.
A reflected cross-site scripting vulnerability has been identified in StoneFly Storage Concentrator (both SC and SCVM) versions prior to 8.0.4.22. The issue arises from unsanitized content being returned in 404 error pages, allowing an attacker to craft a malicious URL. When this URL is visited by an authenticated user, it executes arbitrary scripts in the context of the application within the user's browser session. This vulnerability could be exploited to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 30, 2026CISA-ADP
Assessed Jul 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| StoneFly Storage Concentrator | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
| StoneFly Storage Concentrator Virtual Machine | < 8.0.4.22 < 8.0.4.26 < 8.0.4.29 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 1, 2026 | CVE Modified | CISA-ADP |
| Jun 30, 2026 | New CVE Received | [email protected] |
Volerion