CVE-2026-36226 Benign XSS Verifier

This helper generates a harmless alert-based payload for authorized testing of the Advantech WebAccess/SCADA Create New Project User decryption field. It does not send traffic.

Manual Verification

  1. Log in to an authorized lab instance of Advantech WebAccess/SCADA 8.0-2015.08.16.
  2. Open the Admin Dashboard and navigate to Create New Project User.
  3. Paste the payload into the decryption field.
  4. Save or preview the user record and observe whether the payload executes in the browser.
Ready.