CVE-2026-0489Disclosure

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject specially crafted input which upon user interaction could result in a DOM-based Cross-Site Scripting (XSS) vulnerability. This issue had a low impact on the confidentiality and integrity of the application with no impact on availability.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-10); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-10: 2Mentions · 2026-03-15: 1Technical Details · 2026-03-10: 103-1003-15
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-102
Disclosure2
2026-03-151
General1
Full discourse3 posts
  • Matan Bahar@Bl4ckShad3
    General

    Im happy to share that I found my first CVE (CVE-2026-0489) with Yossi Ayano but definitely not the last. for more info: https://www.cve.org/CVERecord?id=CVE-2026-0489

    Post summary

    The user announces discovery of CVE-2026-0489 and links to its CVE record, but provides no technical or exploit details.

    0004273
    151 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-0489 Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject spec… https://www.cve.org/CVERecord?id=CVE-2026-0489 ----- Traducción: CVE-2026-0489 Deb… http://infoflow.cloud`

    Post summary

    CVE-2026-0489 is disclosed as a flaw in SAP Business One Job Service where insufficient validation of URL query parameters could allow an unauthenticated attacker to inject content; no PoC, exploit, patch, or active exploitation details are provided.

    0000035
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-0489 Due to insufficient validation of user-controlled input in the URLs query parameter. SAP Business One Job Service could allow an unauthenticated attacker to inject spec… https://www.cve.org/CVERecord?id=CVE-2026-0489

    Post summary

    A new vulnerability (CVE‑2026‑0489) is reported in SAP Business One’s Job Service, where insufficient validation of input in the URL query parameter could allow an unauthenticated attacker to perform injection. No further details on exploits or fixes are provided.

    00000189
    56.7K followersView on X

Explore more