# Omega-PSIR Reflected XSS Patched

Published: 2026-02-26 · Severity: low · Sectors: education
Canonical: https://vorant.io/reports/5f316dc5-ffb8-54e7-bb4f-7e02add81579/omega-psir-reflected-xss-patched

> A reflected XSS vulnerability in Omega-PSIR, reported via CERT Polska's coordinated disclosure process, was fixed in version 4.6.7.

CERT Polska coordinated the disclosure of CVE-2026-1434, a reflected cross-site scripting vulnerability affecting the Omega-PSIR software. The flaw resides in the handling of the 'lang' parameter, which fails to properly sanitize user input, allowing an attacker to craft a malicious URL that executes arbitrary JavaScript in a victim's browser when opened.

The vulnerability was responsibly reported by researcher Łukasz Rybak and addressed by the vendor in version 4.6.7. There is no indication of active exploitation in the wild; this is a standard coordinated vulnerability disclosure with a patch already available. Organizations using Omega-PSIR should update to the fixed version to mitigate the risk.

## Mentioned in this report

- Vulnerabilities: CVE-2026-1434

Source reporting: https://cert.pl/en/posts/2026/02/CVE-2026-1434

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/5f316dc5-ffb8-54e7-bb4f-7e02add81579/omega-psir-reflected-xss-patched.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
