📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global supply_chain Software Development and Technology HIGH 3h Global apt Government/Critical Infrastructure CRITICAL 5h Global vulnerability Enterprise Software / Data Analytics CRITICAL 6h Global vulnerability Artificial Intelligence and Technology HIGH 9h Global general Technology and Artificial Intelligence MEDIUM 13h Global general Technology and Artificial Intelligence HIGH 14h Global vulnerability Higher Education CRITICAL 23h Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d Global supply_chain Software Development and Technology HIGH 3h Global apt Government/Critical Infrastructure CRITICAL 5h Global vulnerability Enterprise Software / Data Analytics CRITICAL 6h Global vulnerability Artificial Intelligence and Technology HIGH 9h Global general Technology and Artificial Intelligence MEDIUM 13h Global general Technology and Artificial Intelligence HIGH 14h Global vulnerability Higher Education CRITICAL 23h Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d Global supply_chain Software Development and Technology HIGH 3h Global apt Government/Critical Infrastructure CRITICAL 5h Global vulnerability Enterprise Software / Data Analytics CRITICAL 6h Global vulnerability Artificial Intelligence and Technology HIGH 9h Global general Technology and Artificial Intelligence MEDIUM 13h Global general Technology and Artificial Intelligence HIGH 14h Global vulnerability Higher Education CRITICAL 23h Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global malware Software Development CRITICAL 1d
Vulnerabilities

CVE-2026-26861

High
CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeD
CWE-346 — Weakness Type
Published: Feb 27, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.3
🔗 NVD Official
📄 Description (English)

CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using the includes() method, which can be bypassed by an attacker using a subdomain

🤖 AI Executive Summary

CleverTap Web SDK versions up to 1.15.2 contain a critical Cross-Site Scripting (XSS) vulnerability in the postMessage handler that allows attackers to bypass origin validation using subdomain manipulation. This vulnerability affects customer engagement platforms widely used by Saudi enterprises for marketing automation and customer analytics. Immediate patching is required as the vulnerability enables arbitrary JavaScript execution in the context of affected web applications.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 24, 2026 23:50
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi banking and financial services sector (SAMA-regulated entities) that use CleverTap for customer engagement and marketing analytics. E-commerce platforms, telecommunications companies (STC, Mobily), and government digital services utilizing this SDK are at risk of session hijacking, credential theft, and customer data exfiltration. Healthcare organizations using CleverTap for patient engagement face HIPAA-equivalent compliance violations. The vulnerability enables attackers to inject malicious scripts that can steal authentication tokens, manipulate user interactions, and compromise customer trust in digital platforms.
🏢 Affected Saudi Sectors
Banking and Financial Services E-commerce and Retail Telecommunications Government Digital Services Healthcare Insurance Hospitality and Tourism
⚖️ Saudi Risk Score (AI)
8.1
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all web applications and services using CleverTap Web SDK versions 1.15.2 or earlier
2. Audit postMessage event handlers and origin validation implementations
3. Implement Content Security Policy (CSP) with strict frame-ancestors and script-src directives

PATCHING GUIDANCE:
1. Upgrade CleverTap Web SDK to version 1.15.3 or later immediately
2. Test upgraded SDK in staging environment before production deployment
3. Verify origin validation now uses strict equality (===) instead of includes() method
4. Clear browser caches and CDN caches after deployment

COMPENSATING CONTROLS (if immediate patching not possible):
1. Implement strict Content Security Policy: frame-ancestors 'none'; script-src 'self'
2. Add server-side origin validation for all postMessage communications
3. Implement Sub-Resource Integrity (SRI) for SDK script loading
4. Monitor for suspicious postMessage events in browser console

DETECTION RULES:
1. Monitor for postMessage events with origins containing subdomains of trusted domains
2. Alert on inline script execution attempts from postMessage handlers
3. Track CleverTap SDK version in use across all web properties
4. Implement WAF rules to detect XSS payloads in postMessage communications
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع تطبيقات الويب والخدمات التي تستخدم CleverTap Web SDK الإصدارات 1.15.2 أو أقدم
2. تدقيق معالجات أحداث postMessage وتطبيقات التحقق من الأصل
3. تطبيق سياسة أمان المحتوى (CSP) مع توجيهات صارمة frame-ancestors و script-src

إرشادات التصحيح:
1. ترقية CleverTap Web SDK إلى الإصدار 1.15.3 أو أحدث فوراً
2. اختبار SDK المحدث في بيئة التجريب قبل نشره في الإنتاج
3. التحقق من أن التحقق من الأصل يستخدم الآن المساواة الصارمة (===) بدلاً من طريقة includes()
4. مسح ذاكرة التخزين المؤقت للمتصفح وذاكرة التخزين المؤقت لـ CDN بعد النشر

الضوابط البديلة (إذا لم يكن الإصلاح الفوري ممكناً):
1. تطبيق سياسة أمان محتوى صارمة: frame-ancestors 'none'; script-src 'self'
2. إضافة التحقق من الأصل من جانب الخادم لجميع اتصالات postMessage
3. تطبيق Sub-Resource Integrity (SRI) لتحميل سكريبت SDK
4. مراقبة أحداث postMessage المريبة في وحدة تحكم المتصفح

قواعد الكشف:
1. مراقبة أحداث postMessage مع أصول تحتوي على نطاقات فرعية من النطاقات الموثوقة
2. تنبيه محاولات تنفيذ السكريبت المضمنة من معالجات postMessage
3. تتبع إصدار CleverTap SDK المستخدم عبر جميع خصائص الويب
4. تطبيق قواعد WAF للكشف عن حمولات XSS في اتصالات postMessage
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.14.2.1 - Information security requirements for supplier relationships ECC 2024 A.14.2.5 - Removal of access rights ECC 2024 A.6.1.1 - Information security roles and responsibilities ECC 2024 A.12.6.1 - Management of technical vulnerabilities
🔵 SAMA CSF
SAMA CSF ID.BE-3.1 - Third-party risk management SAMA CSF PR.DS-1 - Data security and privacy SAMA CSF DE.CM-1 - Detection and analysis SAMA CSF RS.MI-1 - Incident mitigation
🟡 ISO 27001:2022
ISO 27001:2022 A.5.23 - Information security for supplier relationships ISO 27001:2022 A.8.1 - User endpoint devices ISO 27001:2022 A.8.3 - Access control ISO 27001:2022 A.14.2 - Supplier service delivery management
🟣 PCI DSS v4.0.1
PCI DSS 6.2 - Security patches and updates PCI DSS 6.5.7 - Cross-site scripting prevention PCI DSS 11.2 - Vulnerability scanning
📊 CVSS Score
8.3
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityL — Low / Local
📋 Quick Facts
Severity High
CVSS Score8.3
CWECWE-346
EPSS0.02%
Exploit No
Patch ✓ Yes
Published 2026-02-27
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.1
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
CWE-346
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.