AdaptiveGRC XSS flaw enables admin takeover
A stored XSS vulnerability in AdaptiveGRC software allows authenticated attackers to steal admin tokens and perform privileged actions.
CERT Polska disclosed CVE-2026-4313, a stored cross-site scripting vulnerability affecting AdaptiveGRC software versions released before December 2025. The flaw exists in text-type fields across forms, where authenticated attackers can inject malicious JavaScript through manipulated HTTP POST requests due to improper parameter validation.
The vulnerability's primary risk is privilege escalation: attackers can use the XSS to capture administrator authentication tokens, enabling them to perform arbitrary actions with administrative privileges. This could serve as a foothold for further compromise of the affected system.
The vulnerability was responsibly disclosed by Antoni Kwietniewski of mBank through CERT Polska's coordinated vulnerability disclosure program. Organizations running AdaptiveGRC should prioritize patching to versions released after December 2025.
Mentioned in this report
Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-4313
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free