CVE-2024-52951: Omada Identity

High severity, CVSS 8.0. EPSS: 1.1% chance of exploitation in the next 30 days.

Stored Cross-Site Scripting in the Access Request History in Omada Identity before version 15 update 1 allows an authenticated attacker to execute arbitrary code in the browser of a victim via a specially crafted link or by viewing a manipulated Access Request History

Affected products

  • Omada Omada Identity: before 15 (fixed in 15)

Published 2024-11-27. Last modified 2026-06-17.