PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-50040 StoneFly CVE debrief

The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie theft, or user redirection. The vulnerability has a CVSS score of 6.1, indicating medium severity. Administrators and users of StoneFly Storage Concentrator, especially those with access to sensitive areas of the application, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system logs for suspicious activity, restricting access to sensitive areas, and implementing compensating controls. Security teams should prioritize patching or mitigating this vulnerability based on the CVSS score and potential impact on the organization. The source item from CISA CSAF provides details on the vulnerability in StoneFly Storage Concentrator. Evidence is based on official records from CISA and CVE.org. The vulnerability allows for reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. Administrators should verify the affected product deployments and review official advisories for mitigation strategies.

Vendor
StoneFly
Product
Storage Concentrator
CVSS
MEDIUM 6.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-06-30
Original CVE updated
2026-06-30
Advisory published
2026-06-30
Advisory updated
2026-06-30

Who should care

Administrators and users of StoneFly Storage Concentrator, especially those with access to sensitive areas of the application, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system logs for suspicious activity, restricting access to sensitive areas, and implementing compensating controls. Security teams should prioritize patching or mitigating this vulnerability based on the CVSS score and potential impact on the organization.

Technical summary

The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie theft, or user redirection. The vulnerability has a CVSS score of 6.1, indicating medium severity.

Defensive priority

Medium priority given the CVSS score of 6.1 and the potential for unauthorized actions

Recommended defensive actions

  • Upgrade to Storage Concentrator version 8.0.4.29 or later
  • Contact StoneFly for additional questions or support
  • Implement compensating controls to detect and prevent similar attacks
  • Monitor systems for suspicious activity
  • Restrict access to sensitive areas of the application

Evidence notes

The source item from CISA CSAF provides details on the vulnerability in StoneFly Storage Concentrator. Evidence is based on official records from CISA and CVE.org. The vulnerability allows for reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. Administrators should verify the affected product deployments and review official advisories for mitigation strategies.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-50040 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-50040

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-50040 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50040

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-06

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.