Cross-site scripting in Angular - CVE-2026-50557
Published: September 11, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary JavaScript in the target user's browser context.
The vulnerability exists due to improper element sanitization and validation in the Angular template preparser when compiling user-controlled templates with custom namespace prefixes. A remote attacker can inject a namespaced script element to execute arbitrary JavaScript in the target user's browser context.
The application must process user-controlled template input at runtime and must not separately sanitize that input before passing it to the Angular compiler.
Affected software
webMethods API Gateway
webMethods ControlPlane
How to mitigate CVE-2026-50557
webMethods API Gateway - update to 11.1 Fix13
webMethods ControlPlane - update to 11.1 Fix11