CVE-2026-90848 | Governikus AusweisApp up to 2.5.4 StartPAOSResponse ResultMessage cross site scripting

SecurityVulns

A vulnerability was found in Governikus AusweisApp up to 2.5.4. It has been declared as problematic. Affected is an unknown function of the component StartPAOSResponse Handler. Executing a manipulation of the argument ResultMessage can lead to cross site scripting.

This vulnerability is tracked as CVE-2026-90848. The attack can be launched remotely. No exploit exists.

It is recommended to upgrade the affected component.

This CVE was requested by the vendor.VulDB Recent EntriesRead More