OVERVIEW: CVE-2026-41468 affects Beghelli Sicuro24 SicuroWeb, which uses an outdated and vulnerable version of AngularJS (1.5.2) containing known sandbox escape primitives. Combined with template injection flaws present in the application, this vulnerability enables attackers to escape the AngularJS sandbox and execute arbitrary JavaScript code within operator browser sessions. The flaw facilitates session hijacking, DOM manipulation, and persistent browser compromise. SEVERITY: The vulnerability carries a CVSS score of 8.7 (HIGH) with an attack vector of adjacent network, requiring no privileges or special user interaction. Attack complexity is low, and the impact spans multiple security domains—confidentiality, integrity, and availability are all affected. Network-adjacent attackers can exploit this via man-in-the-middle attacks on plaintext HTTP deployments, making the threat particularly acute in environments without HTTPS enforcement. EXPLOITATION STATUS: This vulnerability is currently listed on the active Hot List and has been identified as a known exploited vulnerability concern. While the EPSS score of 0.00066 suggests relatively lower exploitation probability across the CVE landscape, the practical attack chain is complete and viable. The combination of outdated component usage with application-level template injection creates a readily exploitable condition for threat actors positioned on the network.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Beghelli | SicuroWeb (Sicuro24) | 0CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.