What is CVE-2026-55730?
CVE-2026-55730 is a Reflected Cross-Site Scripting (XSS) vulnerability in Loytec LWEB-802 before version 5.0.8 on all platforms. It allows an unauthenticated remote attacker to execute arbitrary JavaScript in a victim's browser via a crafted link, potentially performing actions with the victim's privileges. Users should update to version 5.0.8 or later immediately.
Azərbaycanca: CVE-2026-55730 Loytec LWEB-802 platformasında aşkarlanmış Reflected Cross-Site Scripting (XSS) zəifliyidir. 5.0.8 versiyasından əvvəlki bütün platformalarda, autentifikasiya olunmamış uzaqdan hücumçuya xüsusi hazırlanmış keçid vasitəsilə qurbanın brauzerində ixtiyari JavaScript kodu icra etməyə imkan verir. Dərhal proqramı 5.0.8 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Loytec
FAQ2
Which versions of the Loytec LWEB-802 platform are affected by CVE-2026-55730?
All platforms before version 5.0.8 are affected by this vulnerability.
What can an unauthenticated attacker achieve by exploiting CVE-2026-55730?
They can execute arbitrary JavaScript in the victim's browser via a crafted link, potentially performing actions with the victim's privileges.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.