CVE-2026-24343
Analyzed
Analyzed - Analysis Complete
XPath Injection in Apache HertzBeat 1.7.1β1.8.0 Allows Data Manipulation
Publication date: 2026-02-10
Last updated on: 2026-02-11
Assigner: Apache Software Foundation
Description
Description
Improper Neutralization of Data within XPath Expressions ('XPath Injection') vulnerability in Apache HertzBeat.
This issue affects Apache HertzBeat: from 1.7.1 before 1.8.0.
Users are recommended to upgrade to version 1.8.0, which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | hertzbeat | From 1.7.1 (inc) to 1.8.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-643 | The product uses external input to dynamically construct an XPath expression used to retrieve data from an XML database, but it does not neutralize or incorrectly neutralizes that input. This allows an attacker to control the structure of the query. |