PatchSiren cyber security CVE debrief
CVE-2026-50040 StoneFly CVE debrief
The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie theft, or user redirection. The vulnerability has a CVSS score of 6.1, indicating medium severity. Administrators and users of StoneFly Storage Concentrator, especially those with access to sensitive areas of the application, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system logs for suspicious activity, restricting access to sensitive areas, and implementing compensating controls. Security teams should prioritize patching or mitigating this vulnerability based on the CVSS score and potential impact on the organization. The source item from CISA CSAF provides details on the vulnerability in StoneFly Storage Concentrator. Evidence is based on official records from CISA and CVE.org. The vulnerability allows for reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. Administrators should verify the affected product deployments and review official advisories for mitigation strategies.
- Vendor
- StoneFly
- Product
- Storage Concentrator
- CVSS
- MEDIUM 6.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-06-30
- Original CVE updated
- 2026-06-30
- Advisory published
- 2026-06-30
- Advisory updated
- 2026-06-30
Who should care
Administrators and users of StoneFly Storage Concentrator, especially those with access to sensitive areas of the application, should be aware of this vulnerability and take necessary actions to mitigate it. This includes reviewing system logs for suspicious activity, restricting access to sensitive areas, and implementing compensating controls. Security teams should prioritize patching or mitigating this vulnerability based on the CVSS score and potential impact on the organization.
Technical summary
The StoneFly Storage Concentrator is vulnerable to reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. An attacker can craft a malicious URL that, when visited by an authenticated user, causes arbitrary script content to execute within the victim's browser session in the context of the application. This could lead to unauthorized actions, session cookie theft, or user redirection. The vulnerability has a CVSS score of 6.1, indicating medium severity.
Defensive priority
Medium priority given the CVSS score of 6.1 and the potential for unauthorized actions
Recommended defensive actions
- Upgrade to Storage Concentrator version 8.0.4.29 or later
- Contact StoneFly for additional questions or support
- Implement compensating controls to detect and prevent similar attacks
- Monitor systems for suspicious activity
- Restrict access to sensitive areas of the application
Evidence notes
The source item from CISA CSAF provides details on the vulnerability in StoneFly Storage Concentrator. Evidence is based on official records from CISA and CVE.org. The vulnerability allows for reflected cross-site scripting (XSS) due to unsanitized content being echoed back in 404 error pages. This could be leveraged to steal session cookies, redirect users, or perform unauthorized actions on behalf of the victim. Administrators should verify the affected product deployments and review official advisories for mitigation strategies.
Official resources
-
CVE-2026-50040 CVE record
CVE.org
-
CVE-2026-50040 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-06-30T06:00:00.000Z and has not been modified since then.