Published:2026/08/03 Last Updated:2026/08/03
JVN#72334274
Cybozu Garoon vulnerable to cross-site scripting
Overview
Cybozu Garoon provided by Cybozu, Inc contains a cross-site scripting vulnerability.
Products Affected
- Cybozu Garoon versions from 6.17.0 to 6.17.1
Description
Scheduler in Cybozu Garoon provided by Cybozu, Inc contains the following vulnerability:
- Cross-Site Scripting (CWE-79)
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N Base Score 6.0
- CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:H/A:N Base Score 6.8
- CVE-2026-57279
- CyCDB-4148
Impact
An arbitrary script may be executed in the web browser of a user logged in to the product.
Solution
Update the Software
Update the software to the latest version according to the information provided by the developer.
Vendor Status
| Vendor | Status | Last Update | Vendor Notes |
|---|---|---|---|
| Cybozu, Inc. | Vulnerable | 2026/08/03 | Cybozu, Inc. website |
References
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
Cybozu, Inc reported this vulnerability to JPCERT/CC to notify users of its solution through JVN. JPCERT/CC and Cybozu, Inc coordinated under the Information Security Early Warning Partnership.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-57279 |
| JVN iPedia |
JVNDB-2026-000106 |