Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the console component. An attacker who can write to container logs on a managed cluster can inject malicious code into the hub console user's browser session. This occurs when the user views raw pod logs, as the console does not properly escape the log content. Successful exploitation could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the console user. | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. |
| Title | console: console: stored DOM XSS via unescaped pod logs in document.write | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| First Time appeared |
Microsoft
Microsoft sharepoint Server Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:microsoft:sharepoint_server:*:*:*:*:subscription:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2016:*:*:*:*:enterprise:*:*:* cpe:2.3:a:microsoft:sharepoint_server_2019:*:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft sharepoint Server Microsoft sharepoint Server 2016 Microsoft sharepoint Server 2019 |
|
| References |
| |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat console |
|
| Vendors & Products |
Redhat
Redhat console |
Tue, 11 Aug 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A flaw was found in the console component. An attacker who can write to container logs on a managed cluster can inject malicious code into the hub console user's browser session. This occurs when the user views raw pod logs, as the console does not properly escape the log content. Successful exploitation could lead to session hijacking, credential theft, or unauthorized actions performed on behalf of the console user. | |
| Title | console: console: stored DOM XSS via unescaped pod logs in document.write | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-08-11T18:52:04.295Z
Reserved: 2026-07-27T19:02:26.601Z
Link: CVE-2026-66805
No data.
Status : Awaiting Analysis
Published: 2026-08-11T17:19:01.850
Modified: 2026-08-11T18:53:42.910
Link: CVE-2026-66805
OpenCVE Enrichment
Updated: 2026-08-11T14:19:34Z