AdaptiveGRC Stored XSS Enables Admin Takeover
A stored XSS flaw in AdaptiveGRC lets an authenticated attacker hijack admin tokens and take over the platform, patched as of December 2025.
CERT Polska coordinated disclosure of CVE-2026-4313, a stored cross-site scripting vulnerability in AdaptiveGRC governance, risk and compliance software. The flaw stems from improper server-side validation of text-type fields across forms, allowing an authenticated attacker to inject arbitrary JavaScript via a modified HTTP POST request value.
The practical impact is significant within the context of the application: successful exploitation could let an attacker capture an administrator's authentication token, enabling full administrative takeover of the GRC instance and potential further compromise of connected systems or data. The issue affects all versions released before December 2025, implying a fix is already available for current releases.
This was a responsibly disclosed vulnerability with no indication of in-the-wild exploitation; CERT Polska credits Antoni Kwietniewski of mBank for the report. Organizations running AdaptiveGRC should confirm they are on a patched build.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-4313
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free