Published:2026/08/03  Last Updated:2026/08/03

JVN#72334274
Cybozu Garoon vulnerable to cross-site scripting

Overview

Cybozu Garoon provided by Cybozu, Inc contains a cross-site scripting vulnerability.

Products Affected

  • Cybozu Garoon versions from 6.17.0 to 6.17.1

Description

Scheduler in Cybozu Garoon provided by Cybozu, Inc contains the following vulnerability:

  • Cross-Site Scripting (CWE-79)
    • CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N Base Score 6.0
    • CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N Base Score 6.8
    • CVE-2026-57279
    • CyCDB-4148

Impact

An arbitrary script may be executed in the web browser of a user logged in to the product.

Solution

Update the Software
Update the software to the latest version according to the information provided by the developer.

Vendor Status

Vendor Status Last Update Vendor Notes
Cybozu, Inc. Vulnerable 2026/08/03 Cybozu, Inc. website

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Cybozu, Inc reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and Cybozu, Inc coordinated under the Information Security Early Warning Partnership.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-57279
JVN iPedia JVNDB-2026-000106