PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-22233 OPEXUS CVE debrief

CVE-2026-22233 is a medium severity vulnerability in OPEXUS eCASE Audit, allowing an authenticated attacker to save JavaScript as a comment in the 'Estimated Staff Hours' field. The JavaScript is executed whenever another user visits the Project Cost tab. This vulnerability was fixed in OPEXUS eCASE Audit 11.14.2.0. The CVSS score for this vulnerability is 5.5. The vulnerability was published on January 8, 2026.

Vendor
OPEXUS
Product
eCASE Audit
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-08
Original CVE updated
2026-01-08
Advisory published
2026-01-08
Advisory updated
2026-01-08

Who should care

Organizations using OPEXUS eCASE Audit versions prior to 11.14.2.0 should be aware of this vulnerability and take steps to remediate it. Specifically, administrators and users of OPEXUS eCASE Audit should review their system configurations and update to the latest version to prevent exploitation. Additionally, defenders should monitor for potential suspicious activity related to this vulnerability.

Technical summary

CVE-2026-22233 is a stored cross-site scripting (XSS) vulnerability in OPEXUS eCASE Audit. An authenticated attacker can inject JavaScript code as a comment in the 'Estimated Staff Hours' field, which is then executed when another user views the Project Cost tab. The vulnerability has a CVSS score of 5.5 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L. The vulnerability was fixed in OPEXUS eCASE Audit 11.14.2.0.

Defensive priority

Defenders should prioritize remediating this vulnerability by updating OPEXUS eCASE Audit to version 11.14.2.0 or later. Additionally, defenders should monitor for potential suspicious activity related to this vulnerability.

Recommended defensive actions

  • Update OPEXUS eCASE Audit to version 11.14.2.0 or later
  • Monitor for potential suspicious activity related to this vulnerability
  • Review system configurations to ensure proper security controls are in place
  • Implement additional security measures to prevent exploitation, such as input validation and output encoding
  • Consider implementing compensating controls, such as web application firewalls, to detect and prevent exploitation

Evidence notes

The vulnerability was reported by CISA and published on January 8, 2026. The vulnerability has a CVSS score of 5.5 and a CVSS vector of CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L. The vulnerability was fixed in OPEXUS eCASE Audit 11.14.2.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-22233 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-22233

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-22233 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-22233

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-008-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2025/va-26-008-01.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://docs.opexustech.com/docs/oig/audit/eCase_Audit_Release_Notes_11.14.2.0.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.