CVE-2026-12862CWE-148

XLSX formula injection in exports

Medium · published June 22, 2026

CVSS v4.0
5.1
EPSS
0%
Percentile
31.3
In the wild
Unconfirmed
What it is

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.

The record
Technical detail
CVSS v4.0
5.1 · MEDIUM
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
EPSS
0.00382 · 31.3th percentile
Weakness
CWE-148 · Improper Neutralization of Input Leaders
Published
2026-06-22T08:26Z
EPSS history
Timeline
  • 22 JUN 08:26Z
    XLSX formula injection in exports
    cvelistv5