VORANT. Threat Intelligence Sign in Get the full feed

Verint Verba patches stored XSS flaw

low vulnerability

A stored XSS vulnerability in Verint Verba's login logging lets attackers execute scripts in admin browsers via the username field; fixed in 10.0.6.

CERT Polska coordinated the disclosure of CVE-2026-21730, a stored cross-site scripting vulnerability affecting Verint Verba, a call-recording and compliance software platform. The flaw resides in the application's login logging mechanism: when an unauthenticated attacker submits an invalid username/password combination, the unsanitized username value is written directly into application logs. By crafting a malicious payload as the username, an attacker can inject arbitrary JavaScript that executes in the context of an administrator's browser session whenever that admin reviews the log viewer within the web application.

Because the attack requires no authentication and only a failed login attempt, exploitation is trivial to initiate, though it depends on an administrator subsequently viewing the poisoned log entry to trigger execution. Depending on the application's session handling, this could enable session hijacking, unauthorized actions performed as the admin, or further compromise of the administrative interface. The vulnerability was responsibly reported by Jan Czerlunczakiewicz of STM Cyber and has been remediated in Verba version 10.0.6, with no indication of in-the-wild exploitation.

This is a standard coordinated vulnerability disclosure with a vendor patch already available, and there are no reports of active exploitation or public proof-of-concept use. Organizations running Verint Verba should prioritize updating to version 10.0.6 or later to close this exposure.

Mentioned in this report

Vulnerabilities CVE-2026-21730

Source reporting: https://cert.pl/en/posts/2026/05/CVE-2026-21730

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free