CVE-2026-55850 | element-hq Element Web up to 1.12.21 EmbeddedPage.tsx EmbeddedPage cross-domain policy
A vulnerability categorized as problematic has been discovered in element-hq Element Web up to 1.12.21. This issue affects the function EmbeddedPage of the file apps/web/src/components/structures/EmbeddedPage.tsx. Such manipulation leads to permissive cross-domain policy with untrusted domains.
This vulnerability is listed as CVE-2026-55850. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.VulDB Recent EntriesRead More