CVE-2026-48026Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterprise edition, lakeFS Web UI renders markdown files from repository objects without sanitizing the resulting HTML. A user with write access to any repository branch can commit a `.md` object containing arbitrary HTML/JavaScript. Any other user who opens that object, or who navigates to a repository or directory containing a malicious `README.md`, executes the attacker-supplied script in their own authenticated session. lakeFS fixes the issue in v1.81.1 and lakeFS Enterprise fixes the issue in in v1.84.0. Enterprise customers using older versions can temporarily disable Markdown rendering by adding YAML to their config. No workaround exists for OSS release. Users are advised to upgrade to the latest version for both lakeFS and lakeFS-Enterprise.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-08: 2Patch / Workaround · 2026-08-08: 1Technical Details · 2026-08-08: 108-08
Signal classification1 categories
Disclosure
2100.0%
Referenced assets1 URL
By indicator
Full discourse2 posts
  • CyberSignal | Cybersecurity News@XQOPTRX
    Disclosure

    🗄️ lakeFS Web UI vulnerable to stored XSS CVE-2026-48026 affects lakeFS and carries a reported CVSS 8.7 score. An authenticated attacker with repository write access could inject malicious HTML/JavaScript that executes inside the lakeFS Web UI. ⚠️ Technical disclosure: August 7. Additional coverage: August 8. 🔎 Source: TheHackerWire #lakeFS #XSS #AppSec #CVE #CyberSecurity

    Post summary

    The post announces a stored XSS vulnerability (CVE‑2026‑48026) in lakeFS Web UI, detailing attacker conditions and severity, but offers no exploits, patches, or active use evidence.

    0000041
    34 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-48026 lakeFS is an open-source tool that transforms object storage into a Git-like repositories. Prior to version 1.81.1 of the open source edition and 1.84.0 of the enterp… https://www.cve.org/CVERecord?id=CVE-2026-48026

    Post summary

    CVE‑2026‑48026 affects lakeFS versions before 1.81.1 (open‑source) and 1.84.0 (enterprise); the issue is noted in the CVE record, but no PoC, exploit, or active use has been reported.

    00000906
    57.9K followersView on X

Explore more