Medium severity5.4NVD Advisory· Published Feb 2, 2026· Updated Jun 17, 2026
CVE-2026-22881
CVE-2026-22881
Description
Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Cybozu, Inc./Cybozu Garoonv5Range: 5.15.0 to 6.0.3
Patches
Vulnerability mechanics
References
2- jvn.jp/en/jp/JVN35265756/nvdThird Party Advisory
- kb.cybozu.support/article/39084/nvdVendor Advisory
News mentions
0No linked articles in our index yet.