PatchSiren cyber security CVE debrief
CVE-2026-27787 Icz CVE debrief
A cross-site scripting vulnerability was found in MATCHA SNS version 1.3.9 and earlier. Successful exploitation could allow an attacker to execute an arbitrary script on the web browser of a user who accessed the website using the product. This type of vulnerability typically involves injecting malicious scripts into web pages viewed by other users. Users should update to a patched version if available and monitor for suspicious activity. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM.
- Vendor
- Icz
- Product
- Matcha Sns
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-25
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-25
Who should care
Users of MATCHA SNS version 1.3.9 and earlier should be aware of this vulnerability and take steps to mitigate it. This includes updating to a patched version if available and monitoring for suspicious activity. Security teams and administrators responsible for web applications should review the vulnerability details and assess their exposure.
Technical summary
The CVE-2026-27787 vulnerability is a cross-site scripting (XSS) vulnerability in MATCHA SNS version 1.3.9 and earlier. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X. This type of vulnerability typically involves injecting malicious scripts into web pages viewed by other users.
Defensive priority
MEDIUM
Recommended defensive actions
- Update to a patched version if available
- Monitor for suspicious activity
- Implement additional security measures such as input validation and output encoding
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-04-08T06:16:28.480Z and was last modified on 2026-07-25T10:10:00.167Z. The NVD entry is currently Analyzed. The vulnerability affects MATCHA SNS version 1.3.9 and earlier. Users should verify their deployments and review official advisories for mitigation strategies.
Official resources
-
CVE-2026-27787 CVE record
CVE.org
-
CVE-2026-27787 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Third Party Advisory
-
Mitigation or vendor reference
[email protected] - Vendor Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T06:16:28.480Z and has not been modified since then. The NVD entry is currently Analyzed.