CVE-2026-15928
CVE-2026-15928: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.4
High [CVE-2026-15928] Cross-Site Scripting in error page component
CVE-2026-15928Source published Source updated
XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a reflected cross-site scripting (XSS) vulnerability in the error page component. A remote attacker could exploit this by tricking a user into clicking a specially crafted link. Successful exploitation could lead to the execution of malicious scripts in the user's browser, potentially resulting in information disclosure or session hijacking. This reflected cross-site scripting (XSS) vulnerability relies entirely on client-side interaction through a web browser. If executed, the script runs within the context of the user's browser session, making sensitive session tokens or client-side data accessible to the attacker. While external CVSSv4 scoring rates this flaw to an 8.2 High, Red Hat bounds the severity to CVSS 7.4 based…
- Affected products in this advisory
- Red Hat Enterprise Linux 7 Extended Lifecycle Support
- Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
- Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On
- Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
8 more entries in the full advisory.
- Source-reported affected versions
- 1.07
- 1.67.01
- Source-reported fixed versions
- xmlrpc-c-0:1.32.5-1905.svn2451.el7_9.1
- xmlrpc-c-0:1.51.0-11.el8_10.1
- xmlrpc-c-0:1.51.0-5.el8_4.3
- xmlrpc-c-0:1.51.0-6.el8_6.2
14 more entries in the full advisory.
- Mitigation guidance
- To mitigate this issue, ensure that applications utilizing the XMLRPC-C library do not directly expose its error pages to end-users via a web browser. Configure web servers or application frontends to intercept and sanitize or replace error responses originating from XMLRPC-C before they are rendered client-side. Alternatively, restrict XMLRPC-C deployments to backend services that do not present error output in a user-facing web interface.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.