CVE-2026-28280Disclosure(jmpsec / osctrl)

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exists in the `osctrl-admin` on-demand query list. A user with query-level permissions can inject arbitrary JavaScript via the query parameter when running an on-demand query. The payload is stored and executes in the browser of any user (including administrators) who visits the query list page. This can be chained with CSRF token extraction to escalate privileges and take actions as the logged in user. An attacker with query-level permissions (the lowest privilege tier) can execute arbitrary JavaScript in the browsers of all users who view the query list. Depending on their level of access, it can lead to full platform compromise if an administrator executes the payload. The issue is fixed in osctrl `v0.5.0`. As a workaround, restrict query-level permissions to trusted users, monitor query list for suspicious payloads, and/or review osctrl user accounts for unauthorized administrators.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • osctrl

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
osctrl

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-27: 2Mentions · 2026-02-28: 1Technical Details · 2026-02-27: 2Technical Details · 2026-02-28: 102-2702-28
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-272
Disclosure2
2026-02-281
Disclosure1
Full discourse3 posts
  • cvereports@_cvereports
    Disclosure

    CVE-2026-28280: Stored Cross-Site Scripting (XSS) in osctrl-admin On-Demand Query List A Stored Cross-Site Scripting (XSS) vulnerability exists in the `osctrl-admin` component of osctrl versions prior to 0.5.0. The vulnerability allows authenticated u... https://cvereports.com/reports/CVE-2026-28280

    Post summary

    A stored XSS vulnerability in osctrl-admin versions before 0.5.0 is disclosed, with no PoC, exploit, active exploitation, or patch mentioned.

    0000053
    32 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-28280 osctrl is an osquery management solution. Prior to version 0.5.0, a stored cross-site scripting (XSS) vulnerability exists in the `osctrl-admin` on-demand query list.… https://www.cve.org/CVERecord?id=CVE-2026-28280

    Post summary

    The text announces CVE‑2026‑28280, detailing a stored XSS flaw in osctrl‑admin prior to v0.5.0, with no mention of exploits, patches, or active attacks.

    00000145
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-28280 Stored XSS in osctrl-admin On-Demand Query List Before Version 0.5.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-28280

    Post summary

    The text announces a stored XSS vulnerability (CVE-2026-28280) affecting osctrl-admin before version 0.5.0, but does not provide a PoC, exploit, patch, or evidence of active exploitation.

    0000044
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjmpsecosctrl---

Explore more