CVE-2026-12862CWE-148
XLSX formula injection in exports
Medium · published June 22, 2026
What it is
Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment of the user loading the file or other data in the file.
The record
Technical detail
- CVSS v4.0
- 5.1 · MEDIUM
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
- EPSS
- 0.00382 · 31.3th percentile
- Weakness
- CWE-148 · Improper Neutralization of Input Leaders
- Published
- 2026-06-22T08:26Z
EPSS history
Timeline