What is CVE-2026-8152?
CVE-2026-8152 is an open redirect vulnerability in Unblu Spark that can be escalated to a DOM-based cross-site scripting (XSS) attack. When deployed with a same-origin configuration, it allows JavaScript injection into the host application. Affected deployments should review the 'com.unblu.identifier.siteEmbeddedSetup' setting and apply necessary updates.
Azərbaycanca: CVE-2026-8152 Unblu Spark məhsulunda açıq yönləndirmə (open redirect) və DOM-based XSS zəifliyidir. Bu, host tətbiq ilə eyni mənşədə işləyən konfiqurasiyada JavaScript inyeksiyasına səbəb ola bilər. Təsirlənən sistemlərdə 'com.unblu.identifier.siteEmbeddedSetup=true' parametrini nəzarətdə saxlamaq və dərhal yeniləmə tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
In which configuration does the CVE-2026-8152 vulnerability pose a more critical threat in Unblu Spark?
This vulnerability poses a more critical threat when Unblu Spark is deployed in a same-origin configuration with the host application, as it can lead to JavaScript injection.
Which parameter should be reviewed in affected deployments to mitigate the CVE-2026-8152 vulnerability?
The 'com.unblu.identifier.siteEmbeddedSetup' setting should be reviewed in affected deployments.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.