CVE-2026-90848
Publication date 15 September 2026
Last updated 17 September 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting. The attack can be launched remotely. Upgrading to version 2.5.5 is able to address this issue. It is recommended to upgrade the affected component. This CVE was requested by the vendor.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| ausweisapp2 | 26.04 LTS resolute |
Needs evaluation
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
Severity score breakdown
CVSS version:
Base score
5.3 · Medium
Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Base score
4.3 · Medium
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-90848
- https://github.com/Governikus/AusweisApp/commit/6724c548f9ab5f50d674960b5e2a736318815089 (2.5.5)
- https://vuldb.com/cve/CVE-2026-90848
- https://vuldb.com/submit/925923
- https://vuldb.com/vuln/403403
- https://vuldb.com/vuln/403403/cti
- https://www.Governikus.de/loesungen/kundenprojekte/AusweisApp/