MEDIUM

CVE-2026-11878

Microfocus Access Manager 2026-06-24 CVSS v3.1
CVSS
6.1

Description

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS).

This issue affects Access Manager: from 5.1 through 5.1.2.

Summary dbcve.org

OpenText Access Manager versions 5.1 through 5.1.2 contain a cross-site scripting (XSS) vulnerability where user-supplied input is not properly neutralized before being rendered in web pages. This allows authenticated attackers to inject malicious scripts that execute in the context of other users' sessions.

Mitigation

Apply the vendor-supplied patch from OpenText for Access Manager. Until the patch is available, implement WAF rules to filter XSS payloads and sanitize user inputs in affected endpoints.

Weakness (CWE)

CWE-79 Cross-site Scripting (XSS)

EPSS Score

0.22%
Probability of exploitation in next 30 days
12.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE