CVE-2026-79418

EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting (XSS) vulnerability in the Help Chat functionality. Improper neutralization of user-controlled input during web page generation allows authenticated attackers to execute arbitrary JavaScript in the context of other authenticated users, potentially resulting in session hijacking, account takeover, and unauthorized actions.

  • Published Sep 4, 2026
  • CVSS 8.7 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • Public exploit code is available

CVE-2026-79418 at the National Vulnerability Database