CVE 4.6 MEDIUM

Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability_CVE-2026-11443

4.6 / 10
MEDIUM
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N

Description

Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

The specific flaw exists within the downloadAttachment method. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of arbitrary script. An attacker can leverage this vulnerability to execute script in the context of the current user. Was ZDI-CAN-28236.

Basic Information

ID CVE-2026-11443
Source zdi
Published Jun 12, 2026 at 23:04

Affected Product

Vendor Allegra
Product Allegra
Version 8.1.6.22
Affected Versions Allegra Allegra 8.1.6.22

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.