s2
--:--:--UTC

Searching APEX

Starting…

  1. ○ Searching Threats, IOCs & Threat Intelligence locally
  2. ○ Querying external providers
  3. ○ Asking AI Forensic Validator
  4. ○ Creating new entry from validated hit

0s elapsed

CVE-2026-12559

📛 CVE Title

Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for SAP Solutions Capture Validation Application

Description

A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.

Overview

State
PUBLISHED
Assigner (CNA)
OpenText
CVSS severity
HIGH
CVSS score
CVSS 7.3 / 10 7.3 7.3 / 10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/S:N/AU:N/R:U/V:D/RE:M/U:Red
Effective score
7.3 / 10 HIGH source: CNA overview
CWE(s)
CWE-79
Reserved
2026-06-17
Published
2026-09-24 14:18 UTC
Last updated
2026-09-24 14:51 UTC
Source
https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/12xxx/CVE-2026-12559.json
Linked Threat
CVE-2026-12559 — Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for SAP Solutions Capture Validation Application

NVD / KEV / EPSS data refreshed 2026-09-25 04:39 UTC. Re-run the 🛰 Backfill from NVD button above to refresh.

European Union Vulnerability Database ENISA EUVD

ENISA's official EU repository for curated vulnerability intelligence. Carries a separate identifier (EUVD-YYYY-NNNN) and frequently exposes an earlier-published description + CVSS than NVD does.

EUVD ID
EUVD-2026-86008
Assigner
OpenText
Published
Sep 24, 2026, 2:18:21 PM
Updated
Sep 24, 2026, 2:51:31 PM
EUVD base score (CVSS 4.0)
7.3 / 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/S:N/AU:N/R:U/V:D/RE:M/U:Red
EUVD-reported EPSS
0.0000
Vendors
Opentext
Products
Vendor Invoice Management for SAP Solutions (VIM 7.6/20.4 ≤0009)
Vendor Invoice Management for SAP Solutions (VIM 23.4 ≤0004)
Vendor Invoice Management for SAP Solutions (VIM 25.4 ≤0001)
Aliases
GHSA-gmqc-8252-pqjp

ENISA description: A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.

EUVD references (2)

Affected products (1)

VendorProductVersionsPlatforms
OpenText Vendor Invoice Management for SAP Solutions VIM 7.6/20.4 (affected), VIM 23.4 (affected), VIM 25.4 (affected) SAP Fiori

Vendor references (2)

References embedded in the original CVE record by the assigning CNA.

Web references (0)

DuckDuckGo results ranked by threat-intel / vendor advisory domains. Generated by the 🔎 Find references (web) button above — same flow as the Remediations search.

No web references attached yet.

Remediations (10)

Remediations are stored against the linked Threat row; the list below is deduplicated across both pages.

  • web:anonhaven.com

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.

    2026-09-25 10:12 UTC
  • web:cvefeed.io

    The following list is the news that have been mention CVE-2026-12559 vulnerability anywhere in the article. Results are limited to the first 20 news articles due to potential performance issues. The following table lists the changes that have been made to the CVE-2026-12559 vulnerability over time.

    2026-09-25 10:12 UTC
  • web:cvetodo.com

    CVE-2026-12559 : Cross-Site Scripting (XSS) in Vendor Invoice Management For SAP Solutions. Includes technical details, affected versions, and mitigation steps.

    2026-09-25 10:12 UTC
  • web:feedly.com

    CVE-2026-12559 : OpenText reports a stored cross-site scripting flaw in Vendor Invoice Management for SAP Solutions, in the Capture Validation application, that could run unauthorized script in a user's browser.

    2026-09-25 10:12 UTC
  • web:www.aikido.dev

    CVE remediation is fixing known flaws in the software you run. Why upgrading often fails, what remediation actually involves, and how backporting fixes it.

    2026-09-25 10:12 UTC
  • web:www.oracle.com

    This Critical Patch Update contains 1448 new security patches across the product families listed below. Please note that a My Oracle Support (MOS) note summarizing the content of this Critical Patch Update and other Oracle Software Security Assurance activities is located at July 2026 Critical Patch Update: Executive Summary and Analysis.

    2026-09-25 10:12 UTC
  • web:www.oracle.com

    Additional CVEs addressed are: The patch for CVE - 2026 -34481 also addresses CVE - 2026 -34477, CVE - 2026 -34478, CVE - 2026 -34479, and CVE - 2026 -34480. Oracle Fusion Middleware Risk Matrix This Critical Security Patch Update contains 106 new security patches for Oracle Fusion Middleware. 53 of these vulnerabilities may be remotely exploitable without authentication, i.e., may be exploited over a ...

    2026-09-25 10:12 UTC
  • web:www.redsauce.net

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user-s browser, potentially impacting confidentiality and integrity of information processed through the application.

    2026-09-25 10:12 UTC
  • web:www.strix.ai

    How severe is CVE-2026-12559 ? CVE-2026-12559 has a CVSS score of 7.3/10 (HIGH severity). How do I fix CVE-2026-12559 ? Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

    2026-09-25 10:12 UTC
  • web:www.tenable.com

    A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.

    2026-09-25 10:12 UTC

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

Raw JSON

The full cvelistV5 record. Download as CVE-2026-12559.json.

{
  "containers": {
    "adp": [
      {
        "metrics": [
          {
            "other": {
              "content": {
                "id": "CVE-2026-12559",
                "options": [
                  {
                    "Exploitation": "none"
                  },
                  {
                    "Automatable": "no"
                  },
                  {
                    "Technical Impact": "total"
                  }
                ],
                "role": "CISA Coordinator",
                "timestamp": "2026-09-24T14:51:19.732789Z",
                "version": "2.0.3"
              },
              "type": "ssvc"
            }
          }
        ],
        "providerMetadata": {
          "dateUpdated": "2026-09-24T14:51:31.952Z",
          "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "shortName": "CISA-ADP"
        },
        "title": "CISA ADP Vulnrichment"
      }
    ],
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "modules": [
            "SAP Fiori Capture Validation application"
          ],
          "platforms": [
            "SAP Fiori"
          ],
          "product": "Vendor Invoice Management for SAP Solutions",
          "vendor": "OpenText",
          "versions": [
            {
              "lessThanOrEqual": "0009",
              "status": "affected",
              "version": "VIM 7.6/20.4",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "0004",
              "status": "affected",
              "version": "VIM 23.4",
              "versionType": "custom"
            },
            {
              "lessThanOrEqual": "0001",
              "status": "affected",
              "version": "VIM 25.4",
              "versionType": "custom"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "supportingMedia": [
            {
              "base64": false,
              "type": "text/html",
              "value": "<div>A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application.</div>"
            }
          ],
          "value": "A Stored Cross-Site Scripting (XSS) vulnerability has been identified in OpenText Vendor Invoice Management for SAP Solutions Capture Validation application. Under certain conditions, this issue could allow execution of unauthorized script content in a user's browser, potentially impacting confidentiality and integrity of information processed through the application."
        }
      ],
      "impacts": [
        {
          "capecId": "CAPEC-592",
          "descriptions": [
            {
              "lang": "en",
              "value": "CAPEC-592 Stored XSS"
            }
          ]
        }
      ],
      "metrics": [
        {
          "cvssV4_0": {
            "Automatable": "NO",
            "Recovery": "USER",
            "Safety": "NEGLIGIBLE",
            "attackComplexity": "LOW",
            "attackRequirements": "NONE",
            "attackVector": "NETWORK",
            "baseScore": 7.3,
            "baseSeverity": "HIGH",
            "exploitMaturity": "UNREPORTED",
            "privilegesRequired": "HIGH",
            "providerUrgency": "RED",
            "subAvailabilityImpact": "HIGH",
            "subConfidentialityImpact": "HIGH",
            "subIntegrityImpact": "HIGH",
            "userInteraction": "PASSIVE",
            "valueDensity": "DIFFUSE",
            "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H/E:U/S:N/AU:N/R:U/V:D/RE:M/U:Red",
            "version": "4.0",
            "vulnAvailabilityImpact": "NONE",
            "vulnConfidentialityImpact": "HIGH",
            "vulnIntegrityImpact": "HIGH",
            "vulnerabilityResponseEffort": "MODERATE"
          },
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "cweId": "CWE-79",
              "description": "CWE-79 Improper neutralization of input during web page generation ('cross-site scripting')",
              "lang": "en",
              "type": "CWE"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-09-24T14:18:21.380Z",
        "orgId": "f81092c5-7f14-476d-80dc-24857f90be84",
        "shortName": "OpenText"
      },
      "references": [
        {
          "url": "https://support.opentext.com/csm?id=ot_kb_unauthenticated&sysparm_article=KB0869044"
        },
        {
          "url": "https://support.opentext.com/csm?id=kb_article_view&sysparm_article=KB0869040"
        }
      ],
      "source": {
        "discovery": "INTERNAL"
      },
      "title": "Stored Cross-Site Scripting (XSS) in OpenText Vendor Invoice Management for SAP Solutions Capture Validation Application",
      "x_generator": {
        "engine": "Vulnogram 1.0.5"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "f81092c5-7f14-476d-80dc-24857f90be84",
    "assignerShortName": "OpenText",
    "cveId": "CVE-2026-12559",
    "datePublished": "2026-09-24T14:18:21.380Z",
    "dateReserved": "2026-06-17T20:14:40.235Z",
    "dateUpdated": "2026-09-24T14:51:31.952Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2"
}