PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-27787 Icz CVE debrief

A cross-site scripting vulnerability was found in MATCHA SNS version 1.3.9 and earlier. Successful exploitation could allow an attacker to execute an arbitrary script on the web browser of a user who accessed the website using the product. This type of vulnerability typically involves injecting malicious scripts into web pages viewed by other users. Users should update to a patched version if available and monitor for suspicious activity. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM.

Vendor
Icz
Product
Matcha Sns
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-25
Advisory published
2026-04-08
Advisory updated
2026-07-25

Who should care

Users of MATCHA SNS version 1.3.9 and earlier should be aware of this vulnerability and take steps to mitigate it. This includes updating to a patched version if available and monitoring for suspicious activity. Security teams and administrators responsible for web applications should review the vulnerability details and assess their exposure.

Technical summary

The CVE-2026-27787 vulnerability is a cross-site scripting (XSS) vulnerability in MATCHA SNS version 1.3.9 and earlier. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X. This type of vulnerability typically involves injecting malicious scripts into web pages viewed by other users.

Defensive priority

MEDIUM

Recommended defensive actions

  • Update to a patched version if available
  • Monitor for suspicious activity
  • Implement additional security measures such as input validation and output encoding
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-04-08T06:16:28.480Z and was last modified on 2026-07-25T10:10:00.167Z. The NVD entry is currently Analyzed. The vulnerability affects MATCHA SNS version 1.3.9 and earlier. Users should verify their deployments and review official advisories for mitigation strategies.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T06:16:28.480Z and has not been modified since then. The NVD entry is currently Analyzed.