# AdaptiveGRC XSS flaw enables admin takeover

Published: 2026-04-24 · Severity: high
Canonical: https://vorant.io/reports/86f34bed-421a-59bd-aadc-8bf439c80960/adaptivegrc-xss-flaw-enables-admin-takeover

> A stored XSS vulnerability in AdaptiveGRC software allows authenticated attackers to steal admin tokens and perform privileged actions.

CERT Polska disclosed CVE-2026-4313, a stored cross-site scripting vulnerability affecting AdaptiveGRC software versions released before December 2025. The flaw exists in text-type fields across forms, where authenticated attackers can inject malicious JavaScript through manipulated HTTP POST requests due to improper parameter validation.

The vulnerability's primary risk is privilege escalation: attackers can use the XSS to capture administrator authentication tokens, enabling them to perform arbitrary actions with administrative privileges. This could serve as a foothold for further compromise of the affected system.

The vulnerability was responsibly disclosed by Antoni Kwietniewski of mBank through CERT Polska's coordinated vulnerability disclosure program. Organizations running AdaptiveGRC should prioritize patching to versions released after December 2025.

## Mentioned in this report

- Vulnerabilities: CVE-2026-4313

Source reporting: https://cert.pl/en/posts/2026/04/CVE-2026-4313

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/86f34bed-421a-59bd-aadc-8bf439c80960/adaptivegrc-xss-flaw-enables-admin-takeover.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
