What is CVE-2026-48534?
CVE-2026-48534 is a stored cross-site scripting (XSS) vulnerability in the IMAP Server configuration of GFI Archiver before version 15.13. It allows authenticated attackers to inject arbitrary web script or HTML via the server URL parameter at `/Archiver/ImapServerWizard.aspx`, with the payload being stored by the ImapServerWizard component. Users should upgrade to GFI Archiver version 15.13 or later to remediate this issue.
Azərbaycanca: CVE-2026-48534, GFI Archiver-in 15.13 versiyasından əvvəlki versiyalarında IMAP Server konfiqurasiyasında aşkarlanmış stored cross-site scripting (XSS) zəifliyidir. Bu zəiflik autentifikasiya olunmuş hücumçulara `/Archiver/ImapServerWizard.aspx` ünvanında server URL parametri vasitəsilə özbaşına veb skript və ya HTML kodu yeritməyə imkan verir. İstifadəçilərə GFI Archiver-i 15.13 və ya daha yuxarı versiyaya yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: GFI
FAQ2
Is authentication required to exploit CVE-2026-48534?
Yes, this stored XSS vulnerability can only be exploited by authenticated attackers.
What version of GFI Archiver is recommended to remediate CVE-2026-48534?
Users are advised to upgrade to GFI Archiver version 15.13 or later to remediate this issue.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.