9.3
/ 10
CRITICAL
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L
Description
Beghelli Sicuro24 SicuroWeb embeds AngularJS 1.5.2, an end-of-life component containing known sandbox escape primitives. When combined with template injection present in the same application, these primitives allow attackers to escape the AngularJS sandbox and achieve arbitrary JavaScript execution in operator browser sessions, enabling session hijacking, DOM manipulation, and persistent browser compromise. Network-adjacent attackers can deliver the complete injection and escape chain via MITM in plaintext HTTP deployments without active user interaction.
AI Analysis
AngularJS sandbox escape via template injection, allowing arbitrary JavaScript execution in operator browser sessions
Basic Information
ID
CVE-2026-41468
Source
VulnCheck
Published
Apr 22, 2026 at 18:04
Modified
Apr 22, 2026 at 19:05
Affected Product
Vendor
Beghelli
Product
SicuroWeb (Sicuro24)
Affected Versions
Beghelli SicuroWeb (Sicuro24) 0
CWE Classification
AI Assessment
AI Score
9.3 / 10
AI Severity
Critical
Vendor
Beghelli
Product
SicuroWeb (Sicuro24)
References
- www.boffsec-services.com /posts/sicuroweb-cve-2026-22191/
- github.com /kmkz/Exploits/blob/master/2026/CVE-2026-22191-POC.py
- github.com /kmkz/Exploits/blob/master/2026/CVE-2026-22191-SicuroWeb-ATI-chain.txt
- www.beghelli.it
- www.vulncheck.com /advisories/beghelli-sicuro24-sicuroweb-angularjs-sandbox-escape-via-template-injection