← back
CVE-2026-11326

CVE-2026-11326

CVSS 6 MEDIUMEPSS 0.2%CWE-284
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6EPSS 0.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
05 Jun 2026Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atlas 1.2025.288.15 narrows access to these APIs to *.chatgpt.com; users should upgrade to 1.2025.288.15 or later.
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/AU:N/V:D/RE:L/U:Green
Affected products
OpenAI · OpenAI Atlas

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →