PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-18247 BlackBerry CVE debrief

A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session. This vulnerability is particularly concerning for administrators and users of AtHoc IWS, as it could lead to unauthorized actions within the victim's session. The vulnerability has a CVSS score of 5.3, indicating a medium severity level. It is crucial for organizations using AtHoc IWS versions earlier than 7.21 HF-734 to be aware of this potential vulnerability and take necessary precautions to mitigate the risk.

Vendor
BlackBerry
Product
BlackBerry AtHoc IWS
CVSS
MEDIUM 5.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-03
Advisory published
2026-08-11
Advisory updated
2026-09-03

Who should care

Administrators and users of AtHoc IWS versions earlier than 7.21 HF-734 should be aware of this potential vulnerability and take necessary precautions. This includes verifying the version of AtHoc IWS, applying patches, and implementing additional security measures such as input validation and output encoding. Furthermore, organizations should review and update their security policies to include guidance on addressing XSS vulnerabilities and conduct regular security audits to identify and address potential vulnerabilities.

Technical summary

A Cross Site Scripting (XSS) vulnerability in the Web Portals of AtHoc IWS in versions earlier than 7.21 HF-734 could allow an attacker to potentially execute actions in the context of the victim's session. The CVSS score is 5.3, indicating a medium severity vulnerability. This vulnerability is particularly concerning for administrators and users of AtHoc IWS, as it could lead to unauthorized actions within the victim's session. It is essential to address this vulnerability by applying the necessary patches and implementing additional security measures.

Defensive priority

Medium priority given the CVSS score of 5.3 and the potential for XSS attacks.

Recommended defensive actions

  • Verify the version of AtHoc IWS and apply patch 7.21 HF-734 if vulnerable.
  • Implement additional security measures such as input validation and output encoding.
  • Monitor for suspicious activity and implement compensating controls if necessary.
  • Review and update security policies to include guidance on addressing XSS vulnerabilities.
  • Conduct regular security audits to identify and address potential vulnerabilities.

Evidence notes

Evidence is limited; primary official records indicate a potential XSS vulnerability in AtHoc IWS versions earlier than 7.21 HF-734. Further verification is recommended.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-18247 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-18247

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-18247 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-18247

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.