Collax Security Gateway: anonymous reflected cross-site scripting in the WebAccess portal
An unauthenticated attacker who lures a victim to a crafted link runs script in the WebAccess portal origin, because the CGI writes the whole process environment insufficiently escaped into an inline script block.
Advisory ID: TP-2026-070
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: Reflected cross-site scripting (CWE-79)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 9.3 (Critical) · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026
Summary
The WebAccess SSL-VPN user portal at /ak/webaccess is served by webaccess/webaccess.cgi. On every request the CGI walks the whole process environment and serialises each variable into an inline
Root cause
webaccess.cgi:74-78 iterates sort keys %ENV and appends ENV['$var'] = '$val'; for every variable, applying s/\n/\n/g and s/"/\"/g to the value but leaving the wrapping single quote unescaped (webaccess.cgi:76-77).
The accumulated string cgi_env_js is substituted into the
Proof of Concept
Schematically: a single quote is carried in the request path, which browsers preserve literally (the query-string form is inert because browsers encode ' to %27 and the CGI reflects it undecoded).
GET /ak/webaccess/<breakout from the JS string literal with code> HTTP/1.1
Host: gw.example.com
The CGI reflects REQUEST_URI and PATH_INFO raw into the inline script block; the single quote closes the string literal and the injected code runs. The same breakout is reproducible through a request header. Verified at code level on 2026-09-01 under chroot+akrun.
Impact
- Anonymous script execution in the WebAccess portal origin of any victim who opens the link, with no account.
- Theft of portal session material and CSRF tokens readable from that origin, and forgery of portal actions.
- Authenticated VPN users and administrators who open the link execute the payload in their own portal session.
- No CSP or X-Content-Type-Options to constrain the injected script.
References
Is Something Like This in Your Software?
Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.
