MEDIUM
CVE-2026-11878
CVSS
6.1
Description
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS).
This issue affects Access Manager: from 5.1 through 5.1.2.
Summary dbcve.org
OpenText Access Manager versions 5.1 through 5.1.2 contain a cross-site scripting (XSS) vulnerability where user-supplied input is not properly neutralized before being rendered in web pages. This allows authenticated attackers to inject malicious scripts that execute in the context of other users' sessions.
Mitigation
Apply the vendor-supplied patch from OpenText for Access Manager. Until the patch is available, implement WAF rules to filter XSS payloads and sanitize user inputs in affected endpoints.
Weakness (CWE)
CWE-79
Cross-site Scripting (XSS)
EPSS Score
0.22%
Probability of exploitation in next 30 days
12.9th percentile
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.