Collax Security Gateway: anonymous reflected cross-site scripting in the WebAccess portal

An unauthenticated attacker who lures a victim to a crafted link runs script in the WebAccess portal origin, because the CGI writes the whole process environment insufficiently escaped into an inline script block.

Advisory ID: TP-2026-070
Product: Collax Security Gateway (German UTM, firewall, mail and SSL-VPN appliance; also affects Collax Business Server and Groupware Suite)
Vulnerability type: Reflected cross-site scripting (CWE-79)
CVE: pending (MITRE CNA-LR)
CVSS 3.1: 9.3 (Critical) · CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Vendor advisory: Collax release notes CSG 7.2.48
Affected versions: 7.2.46 and earlier
Fixed in: 7.2.48
Reported: 01 September 2026

Summary

The WebAccess SSL-VPN user portal at /ak/webaccess is served by webaccess/webaccess.cgi. On every request the CGI walks the whole process environment and serialises each variable into an inline

Root cause

webaccess.cgi:74-78 iterates sort keys %ENV and appends ENV['$var'] = '$val'; for every variable, applying s/\n/\n/g and s/"/\"/g to the value but leaving the wrapping single quote unescaped (webaccess.cgi:76-77).
The accumulated string cgi_env_js is substituted into the

Proof of Concept

Schematically: a single quote is carried in the request path, which browsers preserve literally (the query-string form is inert because browsers encode ' to %27 and the CGI reflects it undecoded).

GET /ak/webaccess/<breakout from the JS string literal with code> HTTP/1.1
Host: gw.example.com

The CGI reflects REQUEST_URI and PATH_INFO raw into the inline script block; the single quote closes the string literal and the injected code runs. The same breakout is reproducible through a request header. Verified at code level on 2026-09-01 under chroot+akrun.

Impact

  • Anonymous script execution in the WebAccess portal origin of any victim who opens the link, with no account.
  • Theft of portal session material and CSRF tokens readable from that origin, and forgery of portal actions.
  • Authenticated VPN users and administrators who open the link execute the payload in their own portal session.
  • No CSP or X-Content-Type-Options to constrain the injected script.

References

Is Something Like This in Your Software?

Our team found this vulnerability during its work. Have your applications tested by the same specialists, with a penetration test from turingpoint.