CVE-2026-20711

Publication date

2026-02-02 06:37:05

Family

jpcert

State

PUBLISHED

Description

Cross-site scripting vulnerability exists in E-mail function of Cybozu Garoon 5.0.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.