PatchSiren cyber security CVE debrief
CVE-2026-8255 Devs Palace CVE debrief
A weakness has been identified in Devs Palace ERP Online up to 4.0.0. This affects an unknown part of the file /inventory/add_new_customer. The manipulation causes cross site scripting. The attack can be initiated remotely. This vulnerability has a CVSS score of 1.9 and is considered Low severity. Users of Devs Palace ERP Online up to 4.0.0 should be aware of this cross site scripting vulnerability and take necessary precautions, reviewing official advisories and CVE records for further context.
- Vendor
- Devs Palace
- Product
- ERP Online
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-07-24
Who should care
Users of Devs Palace ERP Online up to 4.0.0, operators, and security teams should be aware of this cross site scripting vulnerability. They should review the official advisories and take necessary precautions to prevent exploitation, focusing on affected product scope and potential operational impact.
Technical summary
A cross site scripting vulnerability exists in Devs Palace ERP Online up to 4.0.0. The vulnerability affects an unknown part of the file /inventory/add_new_customer. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Users should review the official CVE record and NVD details for further information, focusing on affected product scope, severity, and vendor guidance.
Defensive priority
Low priority due to CVSS score of 1.9. However, users should still take necessary precautions to prevent exploitation, considering compensating controls and monitoring for suspicious activity.
Recommended defensive actions
- Inventory and verify Devs Palace ERP Online version
- Apply vendor patch if available
- Implement compensating controls such as input validation and output encoding
- Monitor for suspicious activity
- Review official CVE record and NVD details
- Track exceptions and retest remediated assets
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-05-11T00:16:33.960Z and was last modified on 2026-07-24T07:10:00.200Z. The NVD entry is currently Deferred. The vendor was contacted early about this disclosure but did not respond in any way. Users should verify the affected product scope and review official advisories for guidance, focusing on source grounding and evidence limits.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-05-11T00:16:33.960Z and has not been modified since then. The NVD entry is currently Deferred.