CVE-2026-33402 identifies a low-severity cross-site scripting (XSS) vulnerability (CWE-79) in the Sakai Collaboration and Learning Environment (CLE), affecting versions 23.0 through 23.4 and 25.0 through 25.1. This flaw permits malicious scripts to be embedded within group titles and descriptions. The vulnerability has a CVSS v4.0 score of 1.3 (LOW), indicating a network attack vector with low complexity that requires user interaction for exploitation. Potential impact is limited to low security confidentiality and integrity, reflected by a FAUCET Risk Score of 23.0/100. There is currently no evidence of active exploitation, public exploit code, or significant community discussion, and it is not listed on the CISA KEV catalog. Patches are available in Sakai versions 23.5 and 25.2, or a workaround involves checking the SAKAI_SITE_GROUP table.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 23.0, < 23.5CPE matchmatch criteria | cpe:2.3:a:sakailms:sakai:*:*:*:*:*:*:*:* | ||
>= 25.0, < 25.2CPE matchmatch criteria | cpe:2.3:a:sakailms:sakai:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.