CVE-2026-12812: Radware Cyber Controller HTML Injection Vulnerability – Patch Guidance
Radware Cyber Controller versions up to 10.11.0 contain an HTML injection vulnerability in the HTML Report Generation component. An authenticated attacker can inject malicious HTML code that will be rendered in reports viewed by other users. While the vulnerability requires an existing login and user interaction to exploit, the public disclosure and lack of vendor response increase risk. The flaw allows manipulation of report content and appearance but does not enable direct data theft or system crashes.
Source data · NVD / CISA · public domain
- CVSS
- 3.1 · 3.5 LOW · CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
- Weaknesses (CWE)
- CWE-74, CWE-80
- Affected products
- 0 configuration(s)
- Published / Modified
- 2026-06-21 / 2026-06-23
NVD description (verbatim)
A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of the component HTML Report Generation. The manipulation leads to HTML injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
4 reference(s) · View on NVD →
SEC.co analysis · AI-assisted, reviewed against source
Technical summary
CVE-2026-12812 is an HTML injection vulnerability (CWE-74, CWE-80) affecting the report generation subsystem in Radware Cyber Controller. The vulnerability stems from insufficient input sanitization in the HTML Report Generation component, allowing authenticated users to inject arbitrary HTML markup. When a crafted report is viewed by another user, the injected HTML is rendered in the browser context. This is a stored injection variant, meaning the malicious payload persists in generated reports. The CVSS 3.1 score of 3.5 (LOW) reflects the requirement for authenticated access and user interaction, though the integrity impact remains noteworthy for report authenticity.
Business impact
Organizations relying on Cyber Controller for security reporting and compliance documentation face a risk to report integrity and trustworthiness. If attackers inject misleading or malicious HTML into reports, stakeholders consuming those reports—including executives, auditors, and security teams—may receive falsified information or be directed to attacker-controlled resources. In regulated industries where reports feed into compliance and audit processes, this could undermine confidence in security posture assessments. The practical risk depends on whether reports are exported outside the secure network or shared with third parties.
Affected systems
Radware Cyber Controller up to and including version 10.11.0 is affected. The vulnerability has been detected in the HTML Report Generation component. Users running version 10.11.0 or earlier should be considered at risk. Verify your installed version in the Cyber Controller console settings or via API queries to your deployment.
Exploitability
Exploitation requires valid user credentials and relies on social engineering or privilege abuse by an insider or compromised account holder. The attacker must log into Cyber Controller, create or modify a report to inject HTML, and trick another user into viewing that report. The attack is remotely executable over the network but depends on user interaction (viewing the report). Given the public disclosure and the vendor's non-response, threat actors now possess sufficient technical details to craft exploits, elevating the practical risk from theoretical to material.
Remediation
Upgrade Radware Cyber Controller to a version after 10.11.0 when made available by the vendor. Until patched, restrict report generation and viewing privileges to trusted personnel, implement network segmentation to limit access to Cyber Controller from untrusted networks, and educate users not to open reports from untrusted sources or unusual report content. Monitor report generation and access logs for anomalous activity indicating exploitation attempts.
Patch guidance
Monitor Radware's security advisories and product release notes for a patch addressing CVE-2026-12812. Verify patched versions against the official vendor advisory before deploying. Test patches in a non-production environment to ensure compatibility with your Cyber Controller deployment, monitoring integrations with upstream security tools and downstream compliance workflows. Given the vendor's lack of response to early disclosure, obtain official confirmation of patch availability through Radware's support channels before committing to upgrade timelines.
Detection guidance
Monitor Cyber Controller audit logs for unusual report generation activity, especially by service accounts or users with atypical report creation patterns. Look for reports containing suspicious HTML tags (script, iframe, svg, or event handlers in report metadata or content fields). Network detection should focus on outbound HTTP/HTTPS connections from Cyber Controller servers to external domains following report access, which could indicate injected redirect attacks. Review exported or shared reports for unexpected HTML markup or embedded content. Endpoint detection should flag execution of external browsers or tools triggered by Cyber Controller report content.
Why prioritize this
Despite a LOW CVSS score, this vulnerability merits prioritization due to public disclosure, vendor non-responsiveness, and the integrity-critical nature of security reports. In regulated environments or organizations using Cyber Controller for audit documentation, report integrity is a compliance concern. The authenticated-only requirement and user-interaction dependency reduce urgency compared to wormable or pre-auth flaws, but the reputational and compliance risk of falsified security reports justifies near-term remediation planning.
Risk score, explained
The CVSS 3.1 score of 3.5 reflects the conservative weighting of impact (integrity only, no confidentiality or availability loss), accessibility (requires authentication and user interaction), and complexity (low attack complexity once authenticated). However, this numeric score underrepresents business and compliance risk in organizations where Cyber Controller reports feed into board-level or regulatory reporting. Security leaders should contextually elevate priority based on report usage and audience sensitivity, even if the technical severity is low.
Frequently asked questions
What happens if an attacker injects HTML into a report?
The injected HTML is rendered when the report is viewed in a browser, potentially displaying false information, redirecting users to malicious sites, or defacing the report's appearance. The attacker cannot execute JavaScript (due to CWE-80 context and CVSS impact limits), but can mislead users or damage report credibility.
Do I need to update immediately if I'm on version 10.11.0?
Prioritize updates based on how widely Cyber Controller reports are shared and with whom. If reports remain internal and access is restricted to trusted personnel, the risk is lower. If reports are exported for external stakeholders or used in regulatory submissions, update as soon as a patched version is available. In the interim, enforce access controls and log monitoring.
Can this vulnerability be exploited remotely without a user inside the network?
Yes, remote exploitation is possible, but only by someone with valid Cyber Controller credentials. This includes attackers with compromised accounts, disgruntled employees, or attackers who have breached network perimeter controls. The 'remote' classification does not imply zero-authentication attack.
How do I know if my Cyber Controller version is affected?
Check your Cyber Controller console for the version number (usually in Help > About or Settings > System Information). Any version up to and including 10.11.0 is affected. Cross-reference with your deployment documentation and contact Radware support to confirm availability of a patched version for your deployment.
This analysis is based on publicly available vulnerability data and vendor advisories current as of the publication date. The vulnerability details, affected versions, and patch status are subject to change pending vendor response. Organizations should verify all remediation steps against official Radware documentation and test patches in non-production environments before deployment. This document does not constitute a substitute for professional security assessment or vendor support guidance. No exploit code or weaponized proof-of-concept is included; organizations should refer to vendor advisories for authoritative guidance on exploitation vectors and mitigation. Source: NVD (public-domain), retrieved 2026-07-28. Analysis generated by SEC.co (claude-haiku-4-5).
Related vulnerabilities
- CVE-2026-11511LOWBolt CMS HTML Injection Vulnerability – Unsupported Software Risk
- CVE-2025-27511HIGHGeoServer DB2 JNDI Injection Remote Code Execution
- CVE-2025-62198MEDIUMApache Atlas XSS Vulnerability – Exploitation, Patch & Detection
- CVE-2025-71331MEDIUMFlowise XSS Vulnerability in Chat Messages and Agent Functions
- CVE-2026-10060MEDIUMTRENDnet TEW-432BRP Command Injection—End-of-Life Router Vulnerability
- CVE-2026-10061MEDIUMTRENDnet TEW-432BRP Command Injection Vulnerability – Remediation via Replacement
- CVE-2026-10110HIGHSQL Injection in code-projects Student Details Management System 1.0
- CVE-2026-10111HIGHSQL Injection in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0 Login