
CVE-2026-22881 Cross-site scripting vulnerability exists in Message function of Cybozu Garoon 5.15.0 to 6.0.3, which may allow an attacker to reset arbitrary users’ passwords. https://www.cve.org/CVERecord?id=CVE-2026-22881
Post summary
A cross‑site scripting vulnerability in Cybozu Garoon’s Message function (CVE‑2026‑22881) could allow attackers to reset arbitrary users’ passwords.
