CVE-2026-12559

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.

  • Published Sep 24, 2026
  • CVSS 7.3 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-12559 at the National Vulnerability Database