PatchSiren cyber security CVE debrief
CVE-2016-1566 Apache CVE debrief
CVE-2016-1566 is a stored cross-site scripting issue in the Guacamole file browser when file transfer is enabled to a location shared by multiple users. An authenticated remote user can inject arbitrary web script or HTML through a crafted filename, creating a browser-side attack surface for other users of the shared location. The vulnerability was fixed in guacamole.war on 2016-01-13, but the version number was not changed, so version-only checks can miss the remediation.
- Vendor
- Apache
- Product
- Guacamole
- CVSS
- MEDIUM 5.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-02-02
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-02-02
- Advisory updated
- 2026-05-13
Who should care
Administrators and operators of Apache Guacamole deployments, especially environments running 0.9.8 or 0.9.9 with file transfer enabled to shared locations used by multiple users.
Technical summary
NVD classifies the issue as CWE-79 (cross-site scripting) with CVSS 3.0 vector CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The vulnerable behavior is in the file browser: when file transfer is enabled to a shared location, a crafted filename can be rendered in a way that allows stored web script or HTML injection. Because exploitation requires authenticated access and user interaction, the severity is medium, but shared multi-user deployments increase practical risk.
Defensive priority
Medium priority overall; higher priority for shared, multi-user Guacamole deployments that enable file transfer to common locations.
Recommended defensive actions
- Confirm whether your deployed guacamole.war includes the 2016-01-13 fix, since the version number was not changed.
- Upgrade or redeploy Guacamole to a build that contains the stored XSS fix; do not rely on the visible version string alone.
- If file transfer to shared locations is not required, disable it or scope it to per-user locations instead of shared directories.
- Restrict authenticated user permissions so only trusted users can upload or transfer files into shared areas.
- Review application output handling for filenames in the file browser and ensure patched behavior is present in all deployed instances.
Evidence notes
The corpus shows CVE publication on 2017-02-02 and a later metadata modification on 2026-05-13; those are disclosure/record dates, not the issue date. NVD lists affected CPEs for apache:guacamole 0.9.8 and 0.9.9 and assigns CWE-79 with CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N. The referenced advisory states the issue is a stored XSS in the file browser, occurs when file transfer is enabled to a shared location, and was fixed in guacamole.war on 2016-01-13 without a version-number change.
Sources and references
Verified primary and authoritative sources
-
CVE-2016-1566 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2016-1566
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2016-1566 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2016-1566
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://sourceforge.net/p/guacamole/news/2016/02/security-advisory---stored-xss-cve-2016-1566--guac-1465/
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.