CVE-2026-79419

A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia Gestao X Business Suite 8.4 and earlier. The vulnerability is caused by insufficient validation and sanitization of the mensagem parameter in the /Configuracao/Imagens.aspx endpoint, allowing an authenticated attacker to inject arbitrary JavaScript code that is reflected and executed in the context of a victim's browser.

  • Published Sep 4, 2026
  • CVSS 8.7 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • Public exploit code is available

CVE-2026-79419 at the National Vulnerability Database