VYPR
Medium severity6.1NVD Advisory· Published Apr 14, 2026· Updated Apr 21, 2026

CVE-2026-5754

CVE-2026-5754

Description

Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Reflected XSS in Radware Alteon 34.5.4.0 via unsanitized ReturnTo parameter allows script injection in victim's browser.

Vulnerability

Overview

A reflected Cross-Site Scripting (XSS) vulnerability exists in Radware Alteon version 34.5.4.0, specifically in the ReturnTo parameter of the /protected/login route. The root cause is the lack of proper input sanitization; when a user is redirected to a Microsoft SAML login page, the load-balancer reflects the unsanitized ReturnTo parameter back to the user's browser, enabling script injection [1].

Exploitation

An attacker crafts a malicious link containing an XSS payload in the ReturnTo parameter. When the victim clicks the link, they are redirected to the login page, and the load-balancer reflects the malicious payload, causing the attacker's JavaScript to execute in the victim's browser. No authentication is required to trigger the vulnerability, making it accessible to unauthenticated remote attackers [1].

Impact

Successful exploitation allows arbitrary JavaScript execution in the victim's browser, potentially leading to session cookie theft, data exfiltration, unauthorized actions on behalf of the victim, phishing attacks, and damage to the website's reputation [1].

Mitigation

Status

As of the publication date, Radware has acknowledged the vulnerability in their customer portal and plans to release a patch in a future version. No patch or workaround has been publicly available at the time of disclosure [1].

AI Insight generated on May 18, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

1