CVE-2026-24343: Apache Hertzbeat
High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.
Affected products
- Apache Hertzbeat: from 1.7.1, before 1.8.0 (fixed in 1.8.0)
Published 2026-02-10. Last modified 2026-06-17.