5.1
/ 10
MEDIUM
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Description
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template injection and sandbox escape vulnerabilities present in the same application, the absence of CSP removes the browser-enforced restriction that would otherwise block external script execution, enabling attackers to load arbitrary remote payloads into operator browser sessions.
Basic Information
ID
CVE-2026-41469
Source
VulnCheck
Published
Apr 22, 2026 at 18:04
Modified
Apr 22, 2026 at 18:56
Affected Product
Vendor
Beghelli
Product
SicuroWeb (Sicuro24)
Affected Versions
Beghelli SicuroWeb (Sicuro24) 0
CWE Classification
References
- www.boffsec-services.com /posts/sicuroweb-cve-2026-22191/
- github.com /kmkz/Exploits/blob/master/2026/CVE-2026-22191-POC.py
- github.com /kmkz/Exploits/blob/master/2026/CVE-2026-22191-SicuroWeb-ATI-chain.txt
- www.beghelli.it
- www.vulncheck.com /advisories/beghelli-sicuro24-sicuroweb-missing-content-security-policy