PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-89191 SQLView CVE debrief

A stored cross-site scripting vulnerability exists in SQLView KRIS's Workflow Template feature. An attacker with administrative access can inject and store malicious scripts in the 'template name' field, which are then rendered in 'onclick' attributes on the main dashboard without proper sanitization. This allows the scripts to execute in the browsers of affected users.

Vendor
SQLView
Product
SQLView KRIS
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for SQLView KRIS deployments, particularly those with administrative access to the Workflow Template feature, should assess exposure and verify the effectiveness of current input sanitization controls.

Why it matters

A stored cross-site scripting vulnerability in SQLView KRIS's Workflow Template feature allows an attacker with administrative access to inject and store malicious scripts, potentially leading to execution in the browsers of affected users. Defenders should prioritize verifying exposure and assessing the effectiveness of current input sanitization controls.

  • Potential for malicious scripts to execute in the browsers of affected users
  • Possible impact on the integrity of the main dashboard
  • Need for verification of exposure and effectiveness of current controls
  • Priority for implementing additional sanitization controls

Technical summary

The vulnerability exists in the 'template name' field of SQLView KRIS's Workflow Template feature. An attacker with administrative access can inject and store malicious scripts, which are then rendered in 'onclick' attributes on the main dashboard without proper sanitization. This allows the scripts to execute in the browsers of affected users. Defenders should prioritize verifying exposure of SQLView KRIS versions 4.6.4.4 and below, and assess the effectiveness of current input sanitization controls. The CVE Program record and NVD vulnerability detail provide official information about the vulnerability.

Defensive priority

Defenders should prioritize verifying exposure of SQLView KRIS versions 4.6.4.4 and below, and assess the effectiveness of current input sanitization controls.

Recommended defensive actions

  • Verify exposure of SQLView KRIS versions 4.6.4.4 and below
  • Assess the effectiveness of current input sanitization controls
  • Implement additional sanitization controls for user-input data
  • Monitor for suspicious activity on the main dashboard
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. The source item from cve_program_cvelist_v5 offers additional context. A supplemental source reference from CSA is also available.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-89191 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-89191

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-89191 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89191

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Stored Cross-Site Scripting in SQLView KRIS

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/89xxx/CVE-2026-89191.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-136/

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.