
CVE-2026-26861 (CVSS:8.3, HIGH) is Analyzed. CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The han..https://nvd.nist.gov/vuln/detail/CVE-2026-26861 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre
Post summary
The post announces that CleverTap Web SDK v1.15.2 and earlier are vulnerable to XSS via window.postMessage, with a CVSS score of 8.3, but does not provide a PoC, exploit, or patch information.


