PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-50040 StoneFly CVE debrief

The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie theft, or user redirection. The vulnerability has a CVSS score of 6.1, indicating medium severity. Administrators and users of StoneFly Storage Concentrator, especially those with access to sensitive areas of the application, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system logs for suspicious activity, restricting access to sensitive areas, and implementing compensating controls. Security teams should prioritize patching or mitigating this vulnerability based on the CVSS score and potential impact on the organization. The source item from CISA CSAF provides details on the vulnerability in StoneFly Storage Concentrator. Evidence is based on official records from CISA and CVE.org. The vulnerability allows for reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. Administrators should verify the affected product deployments and review official advisories for mitigation strategies.

Vendor
StoneFly
Product
Storage Concentrator
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-06-30
Advisory published
2026-06-30
Advisory updated
2026-06-30

Who should care

Administrators and users of StoneFly Storage Concentrator, especially those with access to sensitive areas of the application, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system logs for suspicious activity, restricting access to sensitive areas, and implementing compensating controls. Security teams should prioritize patching or mitigating this vulnerability based on the CVSS score and potential impact on the organization.

Technical summary

The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie theft, or user redirection. The vulnerability has a CVSS score of 6.1, indicating medium severity.

Defensive priority

Medium priority given the CVSS score of 6.1 and the potential for unauthorized actions

Recommended defensive actions

  • Upgrade to Storage Concentrator version 8.0.4.29 or later
  • Contact StoneFly for additional questions or support
  • Implement compensating controls to detect and prevent similar attacks
  • Monitor systems for suspicious activity
  • Restrict access to sensitive areas of the application

Evidence notes

The source item from CISA CSAF provides details on the vulnerability in StoneFly Storage Concentrator. Evidence is based on official records from CISA and CVE.org. The vulnerability allows for reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. Administrators should verify the affected product deployments and review official advisories for mitigation strategies.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T06:00:00.000Z and has not been modified since then.