CVE-2026-42558Disclosure

LOWCVSS 7.6 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe Sandbox escape in the Xibo CMS allows users with DataSet permissions to use the Data Connector functionality to craft messages which escape the sandbox and facilitate XSS. Exploitation of the vulnerability is possible on behalf of an authorized user who has both of the following privileges, which are not granted to non-admins as standard: Include "Add DataSet" button to allow for additional DataSets to be created independently to Layouts Users should upgrade to version 4.4.2 which fixes this issue. Upgrading to a fixed version is necessary to remediate. Users unable to upgrade should revoke such privileges from users they do not trust.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-116CWE-346

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-05-25); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-25: 1Mentions · 2026-06-11: 1PoC Mentioned / Linked · 2026-05-25: 1Technical Details · 2026-06-11: 105-2506-11
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • 0xRIXET@0xRIXET
    Disclosure

    الحمدلله بهذي الايام الفضيلة ، تم تسجيل ثاني CVE لي CVE-2026-42558 Attack Chain مكون من اربع ثغرات في نظام Xibo CMS Full writeup: https://medium.com/@0xrixet/how-i-found-an-attack-chain-and-got-cve-2026-42558-485e716605da شرحت الهجوم كامل بالرايت اب وكيف قدرت اهرب من الساند بوكس المعزول واسرق بيانات الادمن قراءة ممتعه 🙏🏻

    Post summary

    The author announces the discovery of CVE‑2026‑42558 in Xibo CMS, describing an attack chain that escapes the sandbox and steals admin data, and shares a detailed Medium writeup.

    82040204.9K
    287 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42558 Stored XSS and Iframe Sandbox Escape in Xibo CMS Before 4.4.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42558

    Post summary

    The text announces CVE-2026-42558, describing key technical details (Stored XSS and iframe sandbox escape) but lacks additional context such as PoC, exploitation, or patches.

    0000046
    4.0K followersView on X

Explore more