A vulnerability was found in Winter. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component Brand Settings. The manipulation leads to cross site scripting.

This vulnerability is documented as CVE-2026-32257. The attack can be initiated remotely. There is not any exploit available.