CVE-2026-22881

Publication date

2026-02-02 06:37:17

Family

jpcert

State

PUBLISHED

Description

Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords.