Date: 28th July 2026
Severity: Critical/ High
Audience: Developers building custom applications using Web SDK & Cumulocity environment owners
Action Required: Update custom applications and plugins & upgrade environments
Summary
There are Security vulnerabilities identified within the Web SDK component during our internal security assessment. We have released targeted patches and release updates to address these issues and ensure the continued security of our customers’ environments.
To maintain the integrity of systems, actions are required for both platform administrators and developers.
Affected Versions & Fix Details
Custom applications and plugins
Please identify the Web SDK version currently used to build any custom applications and update your dependencies to the specified version (or higher).
| Release Track | Required version of WebSDK |
|---|---|
| CD | 1023.97.3 or higher |
| Y2026 | 1023.14.x with x >= 180 |
Environment upgrades
| Release Track | Required minimum platform version** |
|---|---|
| CD | The default applications and plugins in all CD environments are fixed |
| Y2026 | y2026.4 will contain all the necessary fixes. |
| Edge | Edge 2026.0.2 will contain all necessary fixes |
Recommended Action
Update custom applications and plugins: Update all custom applications and plugins utilizing the Web SDK to the relevant patched version listed above to ensure you are protected against this vulnerability.
Update environments:
-
Update environments to the y2026.4 maintenance release, or higher.
-
Update Edge to 2026.0.2.
Risk if you do not take action
The vulnerability allows malicious users to construct specially crafted URLs targeting affected applications and plugins. These URLs can be used to alter the visual display of the application, deceive users (for example, via phishing), and potentially lead to data exfiltration by overlaying harmful UI elements.
Support
For further assistance, please contact Cumulocity Support