CVE-2026-1769

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Xerox CentreWare on Windows allows Stored XSS.This issue affects CentreWare: through 7.0.6.  Consider upgrading Xerox® CentreWare Web® to v7.2.2.25 via the software available on Xerox.com
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:xerox:centreware_web:*:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

24 Feb 2026, 20:58

Type Values Removed Values Added
References () https://securitydocs.business.xerox.com/wp-content/uploads/2026/02/Xerox-Security-Bulletin-XRX26-003-for-Xerox-CentreWare-Web.pdf - () https://securitydocs.business.xerox.com/wp-content/uploads/2026/02/Xerox-Security-Bulletin-XRX26-003-for-Xerox-CentreWare-Web.pdf - Vendor Advisory
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:xerox:centreware_web:*:*:*:*:*:*:*:*
First Time Xerox centreware Web
Xerox
Microsoft
Microsoft windows

06 Feb 2026, 18:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-06 18:15

Updated : 2026-02-24 20:58


NVD link : CVE-2026-1769

Mitre link : CVE-2026-1769

CVE.ORG link : CVE-2026-1769


JSON object : View

Products Affected

microsoft

  • windows

xerox

  • centreware_web
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')