Back Sploitus Exploit for Cross-site Scripting in Xerox Centreware_Web
Disclosure timeline and technical write-up for **CVE-2026-1769**, a Stored Cross-Site Scripting vulnerability I identified and responsibly disclosed to Xerox.
- **CVE record:** [cve.org/CVERecord?id=CVE-2026-1769](
- **Vendor security bulletin:** [XRX26-003](
- **CWE:** CWE-79 — Improper Neutralization of Input During Web Page Generation
- **CVSS 3.1:** 5.3 (Medium) — `AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N`
- **Affected software:** Xerox CentreWare Web, up to and including v7.0.6
| Jul 2025 | Vulnerability discovered and reported to Xerox |
| Oct 2025 | Vendor acknowledged the report |
| Feb 2026 | CVE-2026-1769 publicly assigned and published |
- [`WRITEUP.md`](./WRITEUP.md) — technical write-up: vulnerability class, root cause, impact, and remediation guidance
This repository documents the vulnerability at the level already made public by the official CVE record and the vendor's own security bulletin. It does not include exploit code, internal assessment materials, or details beyond what the vendor has already disclosed.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
