What is CVE-2026-66300?
A reflected XSS vulnerability exists in SNOMED International Snowstorm within the 'Web Route' redirection functionality. An attacker can execute arbitrary JavaScript in a victim's browser via a crafted malicious link. Users should immediately upgrade to versions 10.12.2 or 10.9.3 to mitigate the issue.
Azərbaycanca: SNOMED International Snowstorm platformasında 'Web Route' yönləndirmə funksionallığında əks olunan XSS zəifliyi aşkarlanıb. Təcavüzkar xüsusi hazırlanmış link vasitəsilə istifadəçinin brauzerində ixtiyari JavaScript kodunu icra edə bilər. Təsirə məruz qalmamaq üçün dərhal 10.12.2 və ya 10.9.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which platform was the CVE-2026-66300 vulnerability discovered?
It was discovered in the SNOMED International Snowstorm platform, within the 'Web Route' redirection functionality.
Which versions should users upgrade to in order to mitigate CVE-2026-66300?
Users should immediately upgrade to versions 10.12.2 or 10.9.3.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.