Description
Beghelli Sicuro24 SicuroWeb does not enforce a Content Security Policy, allowing unrestricted loading of external JavaScript resources from attacker-controlled origins. When chained with the template injection and sandbox escape vulnerabilities present in the same application, the absence of CSP removes the browser-enforced restriction that would otherwise block external script execution, enabling attackers to load arbitrary remote payloads into operator browser sessions.
Problem types
CWE-693 Protection Mechanism Failure
Product status
Any version
Credits
Jean-Marie Bourbon of Bourbon Offensive Security Services
VulnCheck
References
www.boffsec-services.com/posts/sicuroweb-cve-2026-22191/
github.com/...xploits/blob/master/2026/CVE-2026-22191-POC.py
github.com/...er/2026/CVE-2026-22191-SicuroWeb-ATI-chain.txt
www.beghelli.it
www.vulncheck.com/...curoweb-missing-content-security-policy