Omega-PSIR Reflected XSS Patched
A reflected XSS vulnerability in Omega-PSIR, reported via CERT Polska's coordinated disclosure process, was fixed in version 4.6.7.
CERT Polska coordinated the disclosure of CVE-2026-1434, a reflected cross-site scripting vulnerability affecting the Omega-PSIR software. The flaw resides in the handling of the 'lang' parameter, which fails to properly sanitize user input, allowing an attacker to craft a malicious URL that executes arbitrary JavaScript in a victim's browser when opened.
The vulnerability was responsibly reported by researcher Łukasz Rybak and addressed by the vendor in version 4.6.7. There is no indication of active exploitation in the wild; this is a standard coordinated vulnerability disclosure with a patch already available. Organizations using Omega-PSIR should update to the fixed version to mitigate the risk.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-1434
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free