CVE-2016-0926: Pivotal Software Cloud Foundry Elastic Runtime

Medium severity, CVSS 6.1. EPSS: 1.1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.

Affected products

  • Pivotal Software Cloud Foundry Elastic Runtime: from 1.6.0, before 1.6.32 (fixed in 1.6.32); from 1.7.0, before 1.7.8 (fixed in 1.7.8)

Published 2016-09-18. Last modified 2026-06-17.