Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.This issue affects Sentinel LDK Runtime: before 10.22.
History

Fri, 27 Mar 2026 09:15:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS.This issue affects Sentinel LDK Runtime: before 10.22.
Title Stored XSS vulnerability in Sentinel ACC
First Time appeared Thales
Thales sentinel Ldk Runtime
Weaknesses CWE-79
CPEs cpe:2.3:a:thales:sentinel_ldk_runtime:*:*:windows:*:*:*:*:*
Vendors & Products Thales
Thales sentinel Ldk Runtime
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:L/SI:H/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: THA-PSIRT

Published:

Updated: 2026-03-27T09:05:48.226Z

Reserved: 2026-03-02T19:33:17.694Z

Link: CVE-2026-3457

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-27T09:16:20.543

Modified: 2026-03-27T09:16:20.543

Link: CVE-2026-3457

cve-icon Redhat

No data.