What is CVE-2026-50771?
CVE-2026-50771 is a Cross Site Scripting vulnerability in Squirro Cognitive Search versions prior to 3.14.2, allowing remote attackers to execute arbitrary code via Email Notification, Create Evaluation Sets, and HTML Editor functions. Affected users should immediately upgrade to the latest patched version.
Azərbaycanca: CVE-2026-50771 Squirro Cognitive Search platformasının 3.14.2-dən əvvəlki versiyalarında Email Notification, Create Evaluation Sets və HTML Editor funksiyaları vasitəsilə uzaqdan kod icrasına imkan verən Cross Site Scripting zəifliyidir. Təsirlənmiş istifadəçilər dərhal proqramı ən son versiyaya yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the Squirro Cognitive Search platform are affected by CVE-2026-50771?
This vulnerability affects Squirro Cognitive Search platform versions prior to 3.14.2.
Through which functions can the CVE-2026-50771 Cross Site Scripting vulnerability lead to remote code execution (RCE)?
Attackers can achieve remote code execution through the Email Notification, Create Evaluation Sets, and HTML Editor functions.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.