PatchSiren

Ellucian CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Ellucian CVE published 2026-07-28

CVE-2026-6881

A SQL Injection vulnerability in Ellucian Advance Web and Legacy Advance allows an authenticated attacker to extract sensitive information from databases via a crafted SQL query. This issue affects all versions of Advance Web and Legacy Advance. Defenders should assess exposure, prioritize remediation, and verify the authenticity of user input. The vulnerability is highly critical, with a CVSS score of 9. [truncated]

MEDIUM Ellucian CVE published 2026-06-09

CVE-2026-47106

CVE-2026-47106 is a stored cross-site scripting (XSS) vulnerability in Ellucian Banner Self-Service before the April T2 release (2025-04-23). The vulnerability allows authenticated Banner ERP users to inject malicious payloads into faculty and course fields by exploiting missing HTML encoding during DOM insertion. An attacker with Banner ERP write access can store malicious JavaScript in fields such as fa [truncated]

MEDIUM Ellucian CVE published 2026-06-09

CVE-2026-32856

CVE-2026-32856 is a reflected cross-site scripting (XSS) vulnerability in Ellucian Banner Self-Service before the April T2 release (2025-04-23). The vulnerability allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat request parameter in the dateConverter endpoint. Attackers can craft a malicious URL targeting the una [truncated]