Security advisory: IBEXA-SA-2026-004

Firewall access control issue and XSS vulnerabilities
Publication date:
20/08/2026, 16:49

Severity:
High

Affected versions: Ibexa DXP v4.6.* and Ibexa DXP v5.0.*
Resolving versions: Ibexa DXP v4.6.32 and Ibexa DXP v5.0.10

This security advisory resolves an access control issue and a set of XSS vulnerabilities in the back office.

The access control issue affects only v5.0, not v4.6, and relates to what was fixed in IBEXA-SA-2026-002. On firewalls without a login_path the access_control setting didn't work as expected. This is a critical vulnerability for sites that need access control in such areas. If you have no such custom access control patterns configured, you are not affected.

The XSS issues that were fixed involve these areas of the back office: The Media field preview, the version comparison media diff, the image editor, SuggestionTaggify, the limited user permissions modal, the content type name in Collection block, the storefront cart, and the product code when creating a catalog. These all affect both v5.0 and v4.6.

Back office access is required to encounter these XSS vulnerabilities. This typically means Editor or Administrator role, or similar. The storefront cart issue does affect the front end, but it can't be triggered from there, only from the back office.


Have you found a security bug in Ibexa DXP? See how to report it responsibly here: https://doc.ibexa.co/en/latest/infrastructure_and_maintenance/security/reporting_issues/

All security advisories