CVE-2026-0835 is a cross-site scripting (XSS) vulnerability impacting multiple versions of IBM Sterling B2B Integrator and IBM Sterling File Gateway, allowing an authenticated user to embed arbitrary JavaScript in the Web UI. Rated Medium with a CVSS score of 5.4, this network-exploitable flaw requires low privileges and user interaction, potentially leading to credentials disclosure and altered functionality within a trusted session. Currently, there is no evidence of active exploitation, public exploit code, or significant community and media attention for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.1.0.0, <= 6.1.2.7_2CPE match | cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:* | ||
>= 6.2.0.0, <= 6.2.0.5_1CPE match | cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:* | ||
>= 6.2.1.0, <= 6.2.1.1_1CPE match | cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:* | ||
>= 6.1.0.0, < 6.1.2.8CPE matchmatch criteria | cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:* | ||
>= 6.2.0.0, < 6.2.0.5_2CPE matchmatch criteria | cpe:2.3:a:ibm:sterling_b2b_integrator:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.