What is CVE-2026-57428?
CVE-2026-57428 is an unauthenticated Cross Site Scripting (XSS) vulnerability in Sprout Clients versions 3.2.3 and below. It allows attackers to execute malicious scripts in a user's browser without needing login credentials. Affected systems should be updated to the latest version immediately.
Azərbaycanca: CVE-2026-57428, Sprout Clients plagininin 3.2.3 və daha aşağı versiyalarında autentifikasiya olmadan işləyən Cross Site Scripting (XSS) zəifliyidir. Bu boşluq təcavüzkara istifadəçi brauzerində zərərli skript icra etməyə imkan verə bilər. Təsirlənən sistemlərin ən qısa zamanda son versiyaya yenilənməsi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which plugin is affected by the CVE-2026-57428 vulnerability?
This XSS vulnerability affects Sprout Clients versions 3.2.3 and below.
Is authentication required to exploit CVE-2026-57428?
No, this vulnerability is an unauthenticated XSS flaw, meaning it can be exploited without the attacker needing to log in.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.