PatchSiren

T-Systems CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM T-Systems CVE published 2026-09-18

CVE-2026-92976

A stored Cross-Site Scripting (XSS) vulnerability exists in T-Systems' TAO 2.0 suite's profile management functionality. An authenticated user can inject malicious HTML or JavaScript content into personal data fields, which are stored and displayed unsanitized when viewed by another user, including administrative staff. Successful exploitation could allow JavaScript code execution in the victim's browser, [truncated]