PatchSiren cyber security CVE debrief
CVE-2026-89191 SQLView CVE debrief
A stored cross-site scripting vulnerability exists in SQLView KRIS's Workflow Template feature. An attacker with administrative access can inject and store malicious scripts in the 'template name' field, which are then rendered in 'onclick' attributes on the main dashboard without proper sanitization. This allows the scripts to execute in the browsers of affected users.
- Vendor
- SQLView
- Product
- SQLView KRIS
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for SQLView KRIS deployments, particularly those with administrative access to the Workflow Template feature, should assess exposure and verify the effectiveness of current input sanitization controls.
Why it matters
A stored cross-site scripting vulnerability in SQLView KRIS's Workflow Template feature allows an attacker with administrative access to inject and store malicious scripts, potentially leading to execution in the browsers of affected users. Defenders should prioritize verifying exposure and assessing the effectiveness of current input sanitization controls.
- Potential for malicious scripts to execute in the browsers of affected users
- Possible impact on the integrity of the main dashboard
- Need for verification of exposure and effectiveness of current controls
- Priority for implementing additional sanitization controls
Technical summary
The vulnerability exists in the 'template name' field of SQLView KRIS's Workflow Template feature. An attacker with administrative access can inject and store malicious scripts, which are then rendered in 'onclick' attributes on the main dashboard without proper sanitization. This allows the scripts to execute in the browsers of affected users. Defenders should prioritize verifying exposure of SQLView KRIS versions 4.6.4.4 and below, and assess the effectiveness of current input sanitization controls. The CVE Program record and NVD vulnerability detail provide official information about the vulnerability.
Defensive priority
Defenders should prioritize verifying exposure of SQLView KRIS versions 4.6.4.4 and below, and assess the effectiveness of current input sanitization controls.
Recommended defensive actions
- Verify exposure of SQLView KRIS versions 4.6.4.4 and below
- Assess the effectiveness of current input sanitization controls
- Implement additional sanitization controls for user-input data
- Monitor for suspicious activity on the main dashboard
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE Program record and NVD vulnerability detail provide official information about the vulnerability. The source item from cve_program_cvelist_v5 offers additional context. A supplemental source reference from CSA is also available.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-89191 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-89191
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-89191 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-89191
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Stored Cross-Site Scripting in SQLView KRIS
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/89xxx/CVE-2026-89191.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://www.csa.gov.sg/alerts-and-advisories/alerts/al-2026-136/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.