PatchSiren cyber security CVE debrief
CVE-2026-8254 Devs Palace CVE debrief
A security flaw has been discovered in Devs Palace ERP Online up to 4.0.0. Affected by this issue is some unknown functionality of the file /inventory/sales_save. The manipulation results in cross site scripting. It is possible to launch the attack remotely. This vulnerability has a CVSS score of 1.9 and is considered Low severity. Users of Devs Palace ERP Online up to version 4.0.0 should assess the risk and apply patches or mitigations as available.
- Vendor
- Devs Palace
- Product
- ERP Online
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-07-24
Who should care
Users of Devs Palace ERP Online up to version 4.0.0 should assess the risk and apply patches or mitigations as available. This includes reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
Technical summary
The vulnerability exists in the /inventory/sales_save functionality of Devs Palace ERP Online up to version 4.0.0, allowing for cross-site scripting attacks. The attack can be launched remotely. This vulnerability has a CVSS score of 1.9 and is considered Low severity. Limited details are available about the vulnerability and its impact. Users of Devs Palace ERP Online up to version 4.0.0 should assess the risk and apply patches or mitigations as available, reviewing the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Additional verification is recommended to confirm affected product deployments and ensure proper mitigations are in place.
Defensive priority
Low priority due to CVSS score of 1.9 and lack of detailed exploit information.
Recommended defensive actions
- Inventory and assess instances of Devs Palace ERP Online up to version 4.0.0
- Apply patches or updates if available from the vendor
- Implement compensating controls such as web application firewalls
- Monitor for suspicious activity related to /inventory/sales_save
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-05-11T00:16:33.770Z and has not been modified since. The NVD entry is currently Deferred. Limited details are available about the vulnerability and its impact. The vulnerability exists in the /inventory/sales_save functionality of Devs Palace ERP Online up to version 4.0.0, allowing for cross-site scripting attacks. Users of Devs Palace ERP Online up to version 4.0.0 should assess the risk and apply patches or mitigations as available. The attack can be launched remotely.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-11T00:16:33.770Z and has not been modified since. The NVD entry is currently Deferred.