PatchSiren cyber security CVE debrief
CVE-2026-8262 Devs Palace CVE debrief
A vulnerability was identified in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /accounts/chart-save. Such manipulation leads to cross site scripting. The attack may be performed from remote. The exploit is publicly available and might be used. The vulnerability class is cross-site scripting, which can lead to unauthorized actions on behalf of the user. The affected product is Devs Palace ERP Online, and the likely operational impact is unauthorized data manipulation or theft.
- Vendor
- Devs Palace
- Product
- ERP Online
- CVSS
- LOW 1.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-11
- Original CVE updated
- 2026-07-23
- Advisory published
- 2026-05-11
- Advisory updated
- 2026-07-23
Who should care
Users of Devs Palace ERP Online up to version 4.0.0 should assess the risk of this cross-site scripting vulnerability and take necessary actions to protect their systems. This includes administrators, security teams, and operators who manage or interact with the affected product. Vulnerability management and security teams should prioritize patching or mitigating this vulnerability.
Technical summary
The vulnerability is located in the /accounts/chart-save file of Devs Palace ERP Online up to 4.0.0. An attacker can perform a cross-site scripting attack by manipulating this file. The attack can be performed remotely, and the exploit is publicly available. The technical impact is that an attacker can inject malicious scripts into the application, potentially leading to unauthorized actions. Affected product deployments should be reviewed for exposure, and administrators should consider applying vendor patches or updates if available, implementing compensating controls such as web application firewalls or intrusion detection systems, and monitoring system logs for suspicious activity. The vulnerability class is cross-site scripting, which can lead to unauthorized actions on behalf of the user.
Defensive priority
Medium
Recommended defensive actions
- Inventory and assess the Devs Palace ERP Online system for potential exposure
- Apply vendor patches or updates if available
- Implement compensating controls such as web application firewalls or intrusion detection systems
- Monitor system logs for suspicious activity
- Consider vulnerability scanning and penetration testing
- Review and update incident response plans to address potential cross-site scripting attacks
- Conduct a thorough risk assessment to identify potential vulnerabilities and prioritize remediation efforts
Evidence notes
The CVE record was published on 2026-05-11T02:16:27.930Z and was last modified on 2026-07-23T20:10:00.130Z. The NVD entry is currently Deferred. Evidence is limited to public sources and may not reflect the full scope or impact of this vulnerability. Users should verify the affected product deployments and assess potential exposure with caution.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8262 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8262
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8262 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8262
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://olografix.org/acme/_poc/ERP_Online-POC1.gif
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/submit/809930
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/362559
-
Source reference
Unverified legacy reference
URL: https://vuldb.com/vuln/362559/cti
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.