What is CVE-2026-73158?
CVE-2026-73158 occurs due to insufficient validation of saved graph configuration data in cti-transmute. The `svgIcon` property in these configurations is later interpreted as HTML by Pivotick, posing a risk when configurations created by one user are displayed to others. Affected organizations should apply security updates promptly or restrict the process of loading configurations.
Azərbaycanca: CVE-2026-73158, cti-transmute proqramında saxlanan qrafik konfiqurasiya məlumatlarının kifayət qədər yoxlanılmaması səbəbindən baş verir. Konfiqurasiyadakı `svgIcon` xüsusiyyəti Pivotick tərəfindən HTML kimi şərh edilir ki, bu da bir istifadəçinin yaratdığı zərərli məlumatın digər istifadəçilərə göstərildiyi zaman potensial təhlükə yaradır. Təsirə məruz qalan versiyaları istifadə edən təşkilatlar dərhal təhlükəsizlik yeniləmələrini tətbiq etməli və ya konfiqurasiya yükləmə proseslərini məhdudlaşdırmalıdırlar.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which product was CVE-2026-73158 discovered and what is its cause?
This vulnerability was discovered in cti-transmute. The cause is insufficient validation of saved graph configuration data, specifically the `svgIcon` property.
What measures should organizations take to protect against CVE-2026-73158?
Affected organizations should apply security updates promptly or restrict the process of loading configurations.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.