CVE-2026-24343: Apache Hertzbeat

High severity, CVSS 8.8. EPSS: 0.8% chance of exploitation in the next 30 days.

Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat. This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0. Users are recommended to upgrade to version 1.8.0, which fixes the issue.

Affected products

  • Apache Hertzbeat: from 1.7.1, before 1.8.0 (fixed in 1.8.0)

Published 2026-02-10. Last modified 2026-06-17.