CVE-2026-44925

Cross-Site Request Forgery (CSRF) vulnerability in InfoScale v.9.1.3 Operations Manager (VIOM) allows an attacker to force the user with an active session into clicking a malicious HTML link, which triggers unintended modifications on VIOM web application without the user's knowledge.
Configurations

Configuration 1 (hide)

cpe:2.3:a:veritas:infoscale_operations_manager:*:*:*:*:*:*:*:*

History

21 May 2026, 16:57

Type Values Removed Values Added
First Time Veritas
Veritas infoscale Operations Manager
CPE cpe:2.3:a:veritas:infoscale_operations_manager:*:*:*:*:*:*:*:*
References () https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=1000766080&articleTitle=InfoScale_Operations_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925 - () https://supportinfoscale.cloud.com/support-home/kbsearch/article?articleNumber=1000766080&articleTitle=InfoScale_Operations_Manager_IOM_web_application_Security_Bulletin_for_CVE_2026_44923_CVE_2026_44924_and_CVE_2026_44925 - Vendor Advisory
References () https://www.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-166757640 - () https://www.veritas.com/support/en_US/doc/120571566-166757640-0/viom_tot_v118836641-166757640 - Vendor Advisory

20 May 2026, 20:16

Type Values Removed Values Added
CWE CWE-352
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

20 May 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-20 17:16

Updated : 2026-05-21 16:57


NVD link : CVE-2026-44925

Mitre link : CVE-2026-44925

CVE.ORG link : CVE-2026-44925


JSON object : View

Products Affected

veritas

  • infoscale_operations_manager
CWE
CWE-352

Cross-Site Request Forgery (CSRF)