Multiple Vulnerabilities in NethServer
Posted date 24/08/2026
Identificador
INCIBE-2026-578
Importance
4 - High
Affected Resources
- Webtop component: versions 1.5.6 and earlier.
Description
INCIBE has coordinated the disclosure of two high-severity vulnerabilities affecting the WebTop module integrated into the NethServer collaborative work ecosystem. The vulnerabilities were discovered by Andrea Intilangelo (acme).
These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type for each vulnerability:
- CVE-2026-78331: CVSS v4.0: 8.7 | CVSS AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L | CWE-79
- CVE-2026-78332: CVSS v4.0: 8.2 | CVSS AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L | CWE-79
Solution
The vulnerability has been fixed in version 1.5.7 of the module.
Detail
- CVE-2026-78331: stored XSS in the calendar component of the WebTop module integrated into NethServer, due to a lack of sanitization and encoding in the event fields. Exploitation of this vulnerability could allow an authenticated attacker to inject malicious code, which would execute in the browser of any user viewing the event, enabling arbitrary JavaScript execution, session hijacking, unauthorized access to sensitive data (email, contacts, files), and the performance of unauthorized actions within the platform depending on the victim’s privileges.
- CVE-2026-78332: stored XSS vulnerability in the contacts component of the WebTop module in NethServer due to insufficient sanitization and encoding in the shared address book fields, allowing an authenticated attacker to inject malicious code that executes in the browser of any user viewing the affected contact, resulting in arbitrary JavaScript execution, session compromise, and unauthorized access to confidential information and resources across all integrated groupware services.
CVE
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-78331 | Alta | No | NethServer |
| CVE-2026-78331 | Alta | No | NethServer |
References list
Etiquetas


