Multiple vulnerabilities in T-Systems Products
Posted date 20/08/2026
Identificador
INCIBE-2026-569
Importance
4 - High
Affected Resources
The following products in the TAO 2.0 suite, in versions prior to 2602.00, are affected:
- Conecta: versions prior to 2605.0.0;
- STA: versions prior to 2605.0.0 and 2605.0.1.
Description
INCIBE has coordinated the disclosure of four vulnerabilities—two high-severity and two medium-severity—that affect several products in the TAO 2.0 suite, a management platform for public administration. The vulnerabilities were discovered by T-Systems’ internal security team.
These vulnerabilities have been assigned the following codes, CVSS v4.0 base score, CVSS vector, and CWE vulnerability type for each vulnerability:
- CVE-2026-18225: CVSS v4.0: 8.7 | CVSS AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N | CWE-611
- CVE-2026-18227: CVSS v4.0: 8.2 | CVSS AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N | CWE-287
- CVE-2026-18226: CVSS v4.0: 5.3 | CVSS AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N | CWE-384
- CVE-2026-18224: CVSS v4.0: 5.1 | CVSS AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N | CWE-79
Solution
The vulnerabilities described above have been fixed in version 2605.0.0 of Conecta and version 2605.0.1 of STA. The general recommendation is to update to that version or any later version that includes these fixes.
Detail
- CVE-2026-18225: processing XML documents without restrictions on external entities in Conecta, in versions prior to 2605.0.0, could allow an attacker to access internal resources or cause the disclosure of information not intended by the business logic, primarily affecting confidentiality.
- CVE-2026-18227: inadequate validation of a hash value could, under certain conditions, allow a legitimate user to be impersonated and grant access to their information in the application's private area, compromising the confidentiality and integrity of the data. This vulnerability affects STA, in versions prior to 2605.0.1.
- CVE-2026-18226: inadequate handling of the session identifier in STA, in versions prior to 2605.0.0, could allow an attacker to set a known identifier and, under certain conditions, reuse a legitimate user's session after authentication, compromising the confidentiality and integrity of the session.
- CVE-2026-18224: a Cross-Site Scripting (XSS) vulnerability in the STA product, in versions prior to 2605.0.0, could allow a remote attacker to execute script code in a legitimate user's browser. The attack occurs through unvalidated or improperly encoded parameters in web features accessible to the user. Exploitation requires authentication and/or user interaction, which could compromise the confidentiality and integrity of the user’s session.
CVE
| Identificador CVE | Severidad | Explotación | Fabricante |
|---|---|---|---|
| CVE-2026-18225 | Alta | No | T-Systems |
| CVE-2026-18227 | Alta | No | T-Systems |
| CVE-2026-18226 | Media | No | T-Systems |
| CVE-2026-18224 | Media | No | T-Systems |
References list
Etiquetas


