PatchSiren cyber security CVE debrief
CVE-2026-50040 StoneFly CVE debrief
The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie theft, or user redirection. The vulnerability has a CVSS score of 6.1, indicating medium severity. Administrators and users of StoneFly Storage Concentrator, especially those with access to sensitive areas of the application, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system logs for suspicious activity, restricting access to sensitive areas, and implementing compensating controls. Security teams should prioritize patching or mitigating this vulnerability based on the CVSS score and potential impact on the organization. The source item from CISA CSAF provides details on the vulnerability in StoneFly Storage Concentrator. Evidence is based on official records from CISA and CVE.org. The vulnerability allows for reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. Administrators should verify the affected product deployments and review official advisories for mitigation strategies.
- Vendor
- StoneFly
- Product
- Storage Concentrator
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-06-30
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-06-30
Who should care
Administrators and users of StoneFly Storage Concentrator, especially those with access to sensitive areas of the application, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system logs for suspicious activity, restricting access to sensitive areas, and implementing compensating controls. Security teams should prioritize patching or mitigating this vulnerability based on the CVSS score and potential impact on the organization.
Technical summary
The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie theft, or user redirection. The vulnerability has a CVSS score of 6.1, indicating medium severity.
Defensive priority
Medium priority given the CVSS score of 6.1 and the potential for unauthorized actions
Recommended defensive actions
- Upgrade to Storage Concentrator version 8.0.4.29 or later
- Contact StoneFly for additional questions or support
- Implement compensating controls to detect and prevent similar attacks
- Monitor systems for suspicious activity
- Restrict access to sensitive areas of the application
Evidence notes
The source item from CISA CSAF provides details on the vulnerability in StoneFly Storage Concentrator. Evidence is based on official records from CISA and CVE.org. The vulnerability allows for reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. Administrators should verify the affected product deployments and review official advisories for mitigation strategies.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-50040 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-50040
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-50040 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-50040
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-181-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-181-06
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.