CVE-2026-13083

A flaw was found in the Pen Drive report generator. Cluster-sourced data is rendered into HTML reports without proper escaping or sanitization. An attacker with cluster administrator privileges can inject a stored cross-site scripting (XSS) payload into cluster objects (such as ClusterVersion spec.channel) that executes in the browser of any user who opens the generated HTML report.
References
Link Resource
https://access.redhat.com/security/cve/CVE-2026-13083 Mitigation Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2491886 Issue Tracking Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:redhat:pen_drive:*:*:*:*:*:*:*:*

History

08 Jul 2026, 03:59

Type Values Removed Values Added
CPE cpe:2.3:a:redhat:pen_drive:*:*:*:*:*:*:*:*
References () https://access.redhat.com/security/cve/CVE-2026-13083 - () https://access.redhat.com/security/cve/CVE-2026-13083 - Mitigation, Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2491886 - () https://bugzilla.redhat.com/show_bug.cgi?id=2491886 - Issue Tracking, Vendor Advisory
First Time Redhat pen Drive
Redhat

26 Jun 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-26 00:16

Updated : 2026-07-08 03:59


NVD link : CVE-2026-13083

Mitre link : CVE-2026-13083

CVE.ORG link : CVE-2026-13083


JSON object : View

Products Affected

redhat

  • pen_drive
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')