Security Advisory: Vulnerabilities in WebSDK

Date: 28th July 2026
Severity: Critical/ High
Audience: Developers building custom applications using Web SDK & Cumulocity environment owners
Action Required: Update custom applications and plugins & upgrade environments

Summary


There are Security vulnerabilities identified within the Web SDK component during our internal security assessment. We have released targeted patches and release updates to address these issues and ensure the continued security of our customers’ environments.

To maintain the integrity of systems, actions are required for both platform administrators and developers.

Affected Versions & Fix Details


Custom applications and plugins

Please identify the Web SDK version currently used to build any custom applications and update your dependencies to the specified version (or higher).


Release Track Required version of WebSDK
CD 1023.97.3 or higher
Y2026 1023.14.x with x >= 180

Environment upgrades


Release Track Required minimum platform version**
CD The default applications and plugins in all CD environments are fixed
Y2026 y2026.4 will contain all the necessary fixes.
Edge Edge 2026.0.2 will contain all necessary fixes

Recommended Action


Update custom applications and plugins: Update all custom applications and plugins utilizing the Web SDK to the relevant patched version listed above to ensure you are protected against this vulnerability.

Update environments:

  • Update environments to the y2026.4 maintenance release, or higher.

  • Update Edge to 2026.0.2.

Risk if you do not take action


The vulnerability allows malicious users to construct specially crafted URLs targeting affected applications and plugins. These URLs can be used to alter the visual display of the application, deceive users (for example, via phishing), and potentially lead to data exfiltration by overlaying harmful UI elements.

Support


For further assistance, please contact Cumulocity Support