CVE-2026-8152 Details
Description
Unblu Spark contains an open redirect vulnerability that can be escalated to a DOM-based cross-site scripting (XSS) attack. When Unblu Spark is deployed with com.unblu.identifier.siteEmbeddedSetup=true, it runs in the same origin as the host application. Any JavaScript injected through this vulnerability therefore executes with full access to the host application's cookies, DOM, and same-origin APIs — an attacker can reach all resources of the host application, not just Unblu's. This expanded blast radius is the reason on-premises deployments using this configuration are rated CRITICAL.
A vulnerability in Unblu Spark versions through 8.36.1 that allows open redirects, which can be exploited to perform DOM-based cross-site scripting (XSS) attacks. When deployed with the siteEmbeddedSetup parameter set to true, Unblu Spark runs in the same origin as the host application. This configuration enables any injected JavaScript to execute with full access to the host application's cookies, DOM, and same-origin APIs, allowing an attacker to access all resources of the host application, not just those of Unblu.
Users can upgrade to Unblu Spark version 8.36.1-hotfix.0 or later. After upgrading, review the redirect filter configuration to ensure it meets the desired security standards. For Unblu Cloud customers, no action is needed as the platform automatically applies the necessary protections.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 22, 2026CISA-ADP
Assessed Jul 22, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://docs.unblu.com/latest/security-bulletins/#UBL-2026-001 | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-601 | URL Redirection to Untrusted Site ('Open Redirect') | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Unblu Spark | <= 8.36.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |
Volerion