
Public write-up and disclosure timeline for CVE-2026-1769 (Stored XSS in Xerox CentreWare Web)
Disclosure timeline and technical write-up for CVE-2026-1769, a Stored Cross-Site Scripting vulnerability I identified and responsibly disclosed to Xerox.
AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N| Date | Event |
|---|
| Jul 2025 | Vulnerability discovered and reported to Xerox |
| Oct 2025 | Vendor acknowledged the report |
| Jan 2026 | Vendor released a fix |
| Jan 2026 | Fix confirmed |
| Feb 2026 | CVE-2026-1769 publicly assigned and published |
WRITEUP.md — technical write-up: vulnerability class, root cause, impact, and remediation guidanceThis repository documents the vulnerability at the level already made public by the official CVE record and the vendor's own security bulletin. It does not include exploit code, internal assessment materials, or details beyond what the vendor has already disclosed.