CVE-2022-26962

Italtel NFV 11.1.2-20210318 allows Multiple Stored XSS under NP_BCCAS-RMCTRL-01/IMCSCIWebGui/configuration.jsp?opration=list&object=announcementAS via the name, username, or mrfAnnouncementNameparameter. A malicious user leveraging this vulnerability could inject arbitrary JavaScript. The malicious payload will then be triggered every time an authenticated user browses the page containing it.

  • Published Sep 10, 2026
  • CVSS 5.4 medium
  • 0.2% chance of exploitation in the next 30 days (EPSS)

CVE-2022-26962 at the National Vulnerability Database