Skip to content
Exploit for Cross-site Scripting in Xerox Centreware_Web

Exploit for Cross-site Scripting in Xerox Centreware_Web

Sploitus September 23, 2026

Disclosure timeline and technical write-up for **CVE-2026-1769**, a Stored Cross-Site Scripting vulnerability I identified and responsibly disclosed to Xerox.

- **CVE record:** [cve.org/CVERecord?id=CVE-2026-1769](

- **Vendor security bulletin:** [XRX26-003](

- **CWE:** CWE-79 — Improper Neutralization of Input During Web Page Generation

- **CVSS 3.1:** 5.3 (Medium) — `AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N`

- **Affected software:** Xerox CentreWare Web, up to and including v7.0.6

| Jul 2025 | Vulnerability discovered and reported to Xerox |

| Oct 2025 | Vendor acknowledged the report |

| Feb 2026 | CVE-2026-1769 publicly assigned and published |

- [`WRITEUP.md`](./WRITEUP.md) — technical write-up: vulnerability class, root cause, impact, and remediation guidance

This repository documents the vulnerability at the level already made public by the official CVE record and the vendor's own security bulletin. It does not include exploit code, internal assessment materials, or details beyond what the vendor has already disclosed.

Extracted Entities

Companies (1)

CVEs (1)

Domains (1)

Platforms (1)

Vulnerabilities (1)