CVE-2026-69151

high Red Hat
CVSS v3 Base Score
8.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Confidentiality
High
Integrity
High
Availability
None
Published: August 3, 2026 (34 days ago)
Last Modified: August 3, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in the Angular compiler's internationalization (i18n) pipeline. This vulnerability allows a lower-trust translation file to replace a static event handler with executable JavaScript. A remote attacker could exploit this by injecting malicious scripts, leading to Cross-Site Scripting (XSS). This could result in unauthorized access to sensitive information or actions performed on behalf of the user.

CWE

CWE-79

Affected Products

Red Hat Advanced Cluster Management for Kubernetes 2Red Hat build of Apicurio Registry 3Red Hat Ceph Storage 4Red Hat Enterprise Linux 10Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References