CVE-2026-13083
An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.
Does this matter?
Lower severity and a low EPSS score (0.30%). Track it; it rarely justifies an emergency change on its own.
Description
A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.
- CVSS 3.1
- 6.9 MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:N
- EPSS
- 0.30% probability · 23th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- redhat/pen drive
- Source
- secalert@redhat.com
References
- https://access.redhat.com/security/cve/CVE-2026-13083Mitigation, Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2491886Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.