CVE-2026-26266Disclosure(aliasvault / aliasvault)

LOWCVSS 6.1 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch aliasvault aliasvault systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault Web Client versions 0.25.3 and lower. When viewing received emails on an alias, the HTML content is rendered in an iframe using srcdoc, which does not provide origin isolation. An attacker can send a crafted email containing malicious JavaScript to any AliasVault email alias. When the victim views the email in the web client, the script executes in the same origin as the application. No sanitization or sandboxing was applied to email HTML content before rendering. This vulnerability is fixed in 0.26.0.[

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • aliasvault

Threat summary

  • Patch or workaround signal is available
  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-03); latest day: 3
  • 6 total mentions across 2 days

Affected systems

Vendors
Products
aliasvault

Deep dive

Activity timeline6 mentions / 2d
01223Mentions · 2026-03-03: 3Mentions · 2026-03-04: 3Patch / Workaround · 2026-03-03: 1Technical Details · 2026-03-03: 3Technical Details · 2026-03-04: 303-0303-04
Signal classification3 categories
Disclosure
466.7%
Patch
116.7%
General
116.7%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-033
Disclosure2Patch1
2026-03-043
Disclosure2General1
Full discourse6 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-26266 Stored Cross-Site Scripting in AliasVault Web Client Email Rendering Feature https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-26266

    Post summary

    A stored XSS vulnerability (CVE-2026-26266) was disclosed in AliasVault's web client email rendering feature, with no PoC, exploit, or patch details provided.

    0001057
    4.0K followersView on X
  • The AI generalist@AIengineerlife
    General

    🚨 CVE-2026-26266 - CRITICAL AliasVault Password Manager 🤖 Stored XSS in email rendering. Malicious scripts execute when viewing crafted emails. ThreatScore: 93/100 🔗 http://threatmonitor.io/cve/CVE-2026-26266 #cybersecurity #infosec

    Post summary

    The post announces CVE-2026-26266 as a critical stored XSS vulnerability affecting AliasVault Password Manager, noting malicious script execution when viewing crafted emails, but does not provide a PoC, exploitation details, active exploitation mention, or patch information.

    0000041
    8 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-26266 - Critical AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering feature of AliasVault ... https://www.thehackerwire.com/vulnerability/CVE-2026-26266/ https://t.co/iGnl4gF6TJ

    Post summary

    A stored XSS vulnerability (CVE‑2026‑26266) was disclosed in AliasVault’s email rendering feature, with no PoC, exploit, or patch details provided.

    0000043
    121 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26266: CRITICAL] A cross-site scripting (XSS) vulnerability in AliasVault Web Client versions 0.25.3 and lower allowed attackers to execute malicious scripts via crafted emails. Update to version 0...#cve,CVE-2026-26266,#cybersecurity https://cvefind.com/CVE-2026-26266

    Post summary

    A critical XSS vulnerability in AliasVault Web Client allows malicious script execution via crafted emails; users are advised to update to the latest version.

    0000054
    593 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-26266 AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering f… https://www.cve.org/CVERecord?id=CVE-2026-26266 ----- Traducción: CVE-2026-26266 Ali… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-26266, a stored XSS vulnerability in AliasVault’s email rendering, without providing details on exploitation or mitigation.

    0000042
    55 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26266 AliasVault is a privacy-first password manager with built-in email aliasing. A stored cross-site scripting (XSS) vulnerability was identified in the email rendering f… https://www.cve.org/CVERecord?id=CVE-2026-26266

    Post summary

    A stored XSS vulnerability was identified in AliasVault’s email rendering component, but no PoC, exploit, or patch details are provided.

    00000410
    56.6K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appaliasvaultaliasvault---

Explore more