Back cve.akaoma.com CVE-2026-55879 AKAOMA CVE VULNERABILITIES / 18h OpenReplay is a self-hosted session replay suite. From 1.24.0 before 1.25.0, the OpenReplay tracking SDK accepts custom event names and captured page URLs from any visitor using a public project key, stores them in ClickHouse without output encoding, and later renders them in the authenticated dashboard through TextEllipsis and the event-details modal, allowing an unauthenticated attacker to store script that executes in the dashboard origin, reads
9.3 /10 Critical Risk As a catastrophic security flaw, CVE-2026-55879 has severe implications, demanding immediate intervention.
As a catastrophic security flaw, CVE-2026-55879 has severe implications, demanding immediate intervention.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
