CVE-2025-8386EPSS p4.4%

CVE-2025-8386CVE-2025-8386

Description

The vulnerability, if exploited, could allow an authenticated miscreant (with privilege of "aaConfigTools") to tamper with App Objects' help files and persist a cross-site scripting (XSS) injection that when executed by a victim user, can result in horizontal or vertical escalation of privileges. The vulnerability can only be exploited during config-time operations within the IDE component of Application Server. Run-time components and operations are not affected.

Scoring

CVSS 6.9 ()
VectorCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:L/A:L
EPSS0.16% probability of exploitation · percentile 4.4% · 2026-10-10T12:00:23Z
Last modified2026-10-07
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.