CVE-2026-12862

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.
CVSS

No CVSS.

Configurations

No configuration.

History

22 Jun 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-22 10:16

Updated : 2026-06-23 15:42


NVD link : CVE-2026-12862

Mitre link : CVE-2026-12862

CVE.ORG link : CVE-2026-12862


JSON object : View

Products Affected

No product.

CWE
CWE-148

Improper Neutralization of Input Leaders