CVE-2026-26861 | CleverTap Web SDK up to 1.15.2 nativeDisplay.js includes origin validation (Issue 424 / EUVD-2026-9038)
A vulnerability was found in CleverTap Web SDK up to 1.15.2. It has been declared as critical. Affected by this issue is the function includes of the file src/util/campaignRender/nativeDisplay.js. The manipulation results in origin validation error.
This vulnerability was named CVE-2026-26861. The attack may be performed from remote. There is no available exploit.
It is advisable to implement a patch to correct this issue.