← Vulnerability feed

Vulnerability record · CVE-2022-26974 · published 2 June 2022

CVE-2022-26974: Barco control room management suite cross-site scripting vulnerability

BBarco · Control Room Management Suite

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.

6.1 CVSS 3.1 Medium EPSS 0.55% · top 56.1% CWE-79 · Cross-site scripting
6.1CVSS 3.1 base score, v2 4.3
0.55%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

Barco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a file upload mechanism. Lack of input sanitization in the upload mechanism leads to reflected XSS.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-26974 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2022-26975Barco control room management suite improper authentication vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing log files without authentication.EPSS 0.99%7.5CVE-2022-26233Barco control room management suite path traversal vulnerabilityBarco Control Room Management through Suite 2.9 Build 0275 was discovered to be vulnerable to directory traversal, allowing attackers to access sensi…EPSS 15%6.1CVE-2022-26977Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of i…EPSS 0.55%6.1CVE-2022-26978Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /checklogin.jsp endpoint. The os_use…EPSS 0.55%6.1CVE-2022-26972Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a URL /cgi-bin endpoint. The URL parameter…EPSS 0.55%5.4CVE-2022-26976Barco control room management suite cross-site scripting vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. Lack of i…EPSS 0.44%5.3CVE-2022-26973Barco control room management suite error message information leak vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. By tweaki…EPSS 0.75%5.3CVE-2022-26971Barco control room management suite missing authentication for critical function vulnerabilityBarco Control Room Management Suite web application, which is part of TransForm N before 3.14, is exposing a license file upload mechanism. This uplo…EPSS 0.71%

Source: NIST National Vulnerability Database (record CVE-2022-26974), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.