CVE-2026-18731

Max CVSS: 5.3
Published: August 14, 2026

Xona Systems Security Advisory

XSA-2026-001

Security Vulnerability in Xona SRA Web Session

CVE

CVE-2026-18731

Affected versions

v5.1.0 – v5.5.3

Fixed version

v5.5.4

Severity

Medium (CVSS v4.0: 4.8 / CVSS v3.1: 5.3)

Published

8/14/26

 

A related security vulnerability affecting Manager-connected deployments has been identified and will be addressed in a separate update (XSA-2026-002). A further security advisory will be published when a fix is available. Customers are advised to apply the mitigations described below and upgrade to v5.5.4 as soon as possible.

Summary

A security vulnerability in the Xona SRA web session component could allow an authenticated user with access to a Web Connection to execute commands within the container for that session. The container is isolated and ephemeral, and the session is destroyed when the connection ends.

Xona has no evidence that this vulnerability has been exploited in the wild.

Who is affected

Customers using the web session feature on Xona SRA versions v5.1.0 through v5.5.3. Customers not using web sessions are not affected.

Manager-connected deployments should also refer to XSA-2026-002. When exploited as part of a combined chain, the effective severity increases the severity to Medium / High: CVSS v4.0: 6.3 / CVSS v3.1: 8.8.

What to do

Upgrade to Xona SRA v5.5.4, which contains a fix for this vulnerability. Customers should apply this update immediately.

If immediate upgrade is not possible, the following interim measures reduce risk:

  • Restrict web session access to the minimum required users via RBAC
Enable session recording and live monitoring for all web sessions
  • Enforce session approval workflows

Interim measures reduce risk but do not eliminate the vulnerability. Upgrade to v5.5.4 is the only complete remediation.

Further information

Security teams, researchers, and customers with questions about this vulnerability should contact Xona Support at support@xonasystems.com.