CVE-2026-42558
Xibo Vulnerable to Stored XSS and Iframe Sandbox Escape via Data Connector Script in DataSet
Description
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the Xibo CMS allows users with DataSet permissions to use the Data Connector functionality to craft messages which escape the sandbox and facilitate XSS. Exploitation of the vulnerability is possible on behalf of an authorized user who has both of the following privileges, which are not granted to non-admins as standard: Include "Add DataSet" button to allow for additional DataSets to be created independently to Layouts Users should upgrade to version 4.4.2 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust.
INFO
Published Date :
June 10, 2026, 11:16 p.m.
Last Modified :
July 23, 2026, 9:10 a.m.
Remotely Exploit :
Yes !
Source :
[email protected]
CVSS Scores
| Score | Version | Severity | Vector | Exploitability Score | Impact Score | Source |
|---|---|---|---|---|---|---|
| CVSS | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | |||||
| CVSS 3.1 | HIGH | [email protected] |
Solution
- Upgrade Xibo CMS to version 4.4.2.
- Revoke DataSet privileges if unable to upgrade.
References to Advisories, Solutions, and Tools
Here, you will find a curated list of external links that provide in-depth
information, practical solutions, and valuable tools related to
CVE-2026-42558.
| URL | Resource |
|---|---|
| https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-6389-j56c-9fww |
CWE - Common Weakness Enumeration
While CVE identifies
specific instances of vulnerabilities, CWE categorizes the common flaws or
weaknesses that can lead to vulnerabilities. CVE-2026-42558 is
associated with the following CWEs:
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Attack Pattern Enumeration and Classification
(CAPEC)
stores attack patterns, which are descriptions of the common attributes and
approaches employed by adversaries to exploit the CVE-2026-42558
weaknesses.
We scan GitHub repositories to detect new proof-of-concept exploits. Following list is a collection of public exploits and proof-of-concepts, which have been published on GitHub (sorted by the most recently updated).
Results are limited to the first 15 repositories due to potential performance issues.
The following list is the news that have been mention
CVE-2026-42558 vulnerability anywhere in the article.
The following table lists the changes that have been made to the
CVE-2026-42558 vulnerability over time.
Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability's severity, exploitability, or other characteristics.
-
CVE Translated by [email protected]
Jul. 23, 2026
Action Type Old Value New Value Added Translation Title: Xibo-cms de xibosignage, Description: Xibo es una plataforma de señalización digital de código abierto con un sistema de gestión de contenido web y software de reproductor de pantalla para Windows. Antes de la versión 4.4.2, una cadena de vulnerabilidades que consiste en XSS Almacenado y escape de Sandbox de Iframe en el CMS de Xibo permite a los usuarios con permisos de DataSet utilizar la funcionalidad de Conector de Datos para crear mensajes que escapan del sandbox y facilitan XSS. La explotación de la vulnerabilidad es posible por parte de un usuario autorizado que tiene ambos de los siguientes privilegios, los cuales no se otorgan a usuarios no administradores de forma estándar: Incluir el botón 'Añadir DataSet' para permitir que se creen DataSets adicionales independientemente de los Diseños. Los usuarios deberían actualizar a la versión 4.4.2, la cual corrige este problema. La actualización a una versión corregida es necesaria para remediar. Los usuarios que no puedan actualizar deberían revocar dichos privilegios a los usuarios en los que no confían. -
CVE Modified by [email protected]
Jun. 17, 2026
Action Type Old Value New Value Added Affected [{'vendor': 'xibosignage', 'product': 'xibo-cms', 'versions': [{'status': 'affected', 'version': '< 4.4.2'}]}] -
CVE Modified by 134c704f-9b21-4f2e-91b3-4a467353bcc0
Jun. 17, 2026
Action Type Old Value New Value Added SSVC {'id': 'CVE-2026-42558', 'role': 'CISA Coordinator', 'options': [{'exploitation': 'none'}, {'automatable': 'no'}, {'technicalImpact': 'partial'}], 'version': '2.0.3', 'timestamp': '2026-06-11T12:45:18.666402Z'} -
New CVE Received by [email protected]
Jun. 10, 2026
Action Type Old Value New Value Added Description Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the Xibo CMS allows users with DataSet permissions to use the Data Connector functionality to craft messages which escape the sandbox and facilitate XSS. Exploitation of the vulnerability is possible on behalf of an authorized user who has both of the following privileges, which are not granted to non-admins as standard: Include "Add DataSet" button to allow for additional DataSets to be created independently to Layouts Users should upgrade to version 4.4.2 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust. Added CVSS V3.1 AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:L/A:N Added CWE CWE-79 Added CWE CWE-116 Added CWE CWE-346 Added Reference https://github.com/xibosignage/xibo-cms/security/advisories/GHSA-6389-j56c-9fww