VORANT. Threat Intelligence Sign in Get the full feed

Omega-PSIR Reflected XSS Patched

low vulnerability education

A reflected XSS vulnerability in Omega-PSIR, reported via CERT Polska's coordinated disclosure process, was fixed in version 4.6.7.

CERT Polska coordinated the disclosure of CVE-2026-1434, a reflected cross-site scripting vulnerability affecting the Omega-PSIR software. The flaw resides in the handling of the 'lang' parameter, which fails to properly sanitize user input, allowing an attacker to craft a malicious URL that executes arbitrary JavaScript in a victim's browser when opened.

The vulnerability was responsibly reported by researcher Łukasz Rybak and addressed by the vendor in version 4.6.7. There is no indication of active exploitation in the wild; this is a standard coordinated vulnerability disclosure with a patch already available. Organizations using Omega-PSIR should update to the fixed version to mitigate the risk.

Mentioned in this report

Vulnerabilities CVE-2026-1434

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-1434

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free