A vulnerability was found in OpenAkita up to 1.27.12. It has been declared as problematic. This vulnerability affects unknown code of the file /api/upload of the component File Upload API. The manipulation of the argument File results in cross site scripting.
This vulnerability was named CVE-2026-18682. The attack may be performed from remote. In addition, an exploit is available.
The vendor was contacted early about this disclosure but did not respond in any way.