PatchSiren cyber security CVE debrief
CVE-2026-8255 Devs Palace CVE debrief
A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. The manipulation causes cross site scripting. The attack can be initiated remotely. This vulnerability has a CVSS score of 1.9 and is considered Low severity. Users of Devs Palace ERP Online up to 4.0.0 should be aware of this cross site scripting vulnerability and take necessary precautions, reviewing official advisories and CVE records for further context.
- Vendor
- Devs Palace
- Product
- ERP Online
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-07-24
Who should care
Users of Devs Palace ERP Online up to 4.0.0, operators, and security teams should be aware of this cross site scripting vulnerability. They should review the official advisories and take necessary precautions to prevent exploitation, focusing on affected product scope and potential operational impact.
Technical summary
A cross site scripting vulnerability exists in Devs Palace ERP Online up to 4.0.0. The vulnerability affects an unknown part of the file /inventory/add_new_customer. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Users should review the official CVE record and NVD details for further information, focusing on affected product scope, severity, and vendor guidance.
Defensive priority
Low priority due to CVSS score of 1.9. However, users should still take necessary precautions to prevent exploitation, considering compensating controls and monitoring for suspicious activity.
Recommended defensive actions
- Inventory and verify Devs Palace ERP Online version
- Apply vendor patch if available
- Implement compensating controls such as input validation and output encoding
- Monitor for suspicious activity
- Review official CVE record and NVD details
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-05-11T00:16:33.960Z and was last modified on 2026-07-24T07:10:00.200Z. The NVD entry is currently Deferred. The vendor was contacted early about this disclosure but did not respond in any way. Users should verify the affected product scope and review official advisories for guidance, focusing on source grounding and evidence limits.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8255 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8255
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8255 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8255
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://olografix.org/acme/_poc/ERP_Online-POC1.gif
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/808526
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/362552
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/362552/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.