VYPR
Medium severity6.1NVD Advisory· Published Apr 29, 2026· Updated Apr 30, 2026

CVE-2025-56534

CVE-2025-56534

Description

A cross-site scripting (XSS) vulnerability in the custom authenticator driver of opennebula v6.10.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in OpenNebula's custom authenticator driver allows attackers to execute arbitrary scripts via crafted payload, affecting versions before 7.0.

Vulnerability

Overview CVE-2025-56534 is a stored cross-site scripting (XSS) vulnerability in the custom authenticator driver of OpenNebula, specifically in the Sunstone web interface (opennebula-sunstone). The flaw exists because user-supplied input is not properly sanitized before being stored and later rendered in the administrative interface, allowing an attacker to inject arbitrary HTML or JavaScript. The issue affects OpenNebula versions prior to 7.0, with version 6.10.0.1 confirmed vulnerable [2].

Exploitation

To exploit this vulnerability, an attacker must have access to the OpenNebula Sunstone web interface and be able to submit a crafted payload through the custom authenticator driver. The provided proof-of-concept uses an <image src=q onerror=prompt(8)> tag to demonstrate stored XSS [2]. No authentication is explicitly required for the vulnerable component, but the attacker typically needs to be an authenticated user with permissions to configure authentication drivers or trigger the rendering of the malicious input.

Impact

Successful exploitation allows the attacker to execute arbitrary web scripts or HTML in the context of the victim's browser when they view the affected page. This can lead to session hijacking, credential theft, defacement, or other malicious actions within the Sunstone interface. Since Sunstone is the primary web management console for OpenNebula, an attacker could potentially compromise the entire cloud management interface [2].

Mitigation

The vulnerability is fixed in OpenNebula 7.0 [1][2]. Users running versions prior to 7.0 should upgrade immediately. No workarounds are documented; however, restricting access to the Sunstone web interface and applying strict input validation may reduce risk until a patch is applied.

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:opennebula:opennebula:*:*:*:*:*:*:*:*range: <7.0.0
    • (no CPE)range: =6.10.0.1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.