Top/Articles/Cybozu Garoon CVE-2026-57279 affects only 6.17.0 and 6.17.1
cybozu-garoon-cve-cover-en

Cybozu Garoon CVE-2026-57279 affects only 6.17.0 and 6.17.1

A cross-site scripting flaw in Cybozu Garoon affects just two package-edition releases, 6.17.0 and 6.17.1. Fixed in 6.17.2. Here is how to tell in one check.

NewsPublished Aug. 3, 2026 Updated today
Table of contents
Key takeaways

A cross-site scripting flaw in Cybozu Garoon affects just two package-edition releases, 6.17.0 and 6.17.1. Fixed in 6.17.2. Here is how to tell in one check.

Cybozu's groupware product Garoon has a flaw that lets arbitrary code run inside the browser of a logged-in user. The identifier is CVE-2026-57279, published on August 3, 2026 as JVN#72334274.

The conclusion first. Only two versions are affected: 6.17.0 and 6.17.1 of the on-premises package edition. Anything older is unaffected, and so is 6.17.2 and later. Cybozu's defect notice states the fix landed in 6.17.2.

A headline saying "vulnerability in Garoon" is enough to make anyone nervous, given the product is used at a reported 90,000-plus companies. For this particular flaw, though, the set of organizations that actually qualify is small. What follows is arranged so you can decide whether you are one of them in the shortest possible time.

ItemDetail
IdentifierCVE-2026-57279
Tracking IDsCyVDB-4148 / JVN#72334274
AffectedGaroon package edition
6.17.0 / 6.17.1 only
FeatureScheduler
TypeCross-site scripting
(code running in someone else's browser)
PreconditionsValid login required
plus victim interaction
Severity (CVSS)6.0 (v4.0) / 6.8 (v3.0)
Fixed in6.17.2
ExploitationNo reports

How to tell whether this applies to you

Three checks and you are done.

What to checkVerdict
You use the cloud editionThis notice targets the package edition
(see below)
Version is 6.17.0 or 6.17.1Affected. Move to 6.17.2
Version is 6.17.2 or laterNot affected
6.16 or earlier / Garoon 5 or earlierNot affected by this one
(but see the caveat below)

The version is visible in the top right of the screen after logging in, or from the system administration pages. If you are unsure, ask your IT department or the reseller who installed it β€” for the version number, not the product name.

Note that the notice Cybozu issued covers the "package edition" of Garoon. Its security bulletin says nothing about the cloud edition. But since there is also no sentence stating that the cloud edition is unaffected, we are recording the cloud edition as unconfirmed. Cybozu updates the cloud service on its own side so customers generally have nothing to do β€” but that is a general statement about how the service works, not an official position on this particular flaw.

What the flaw actually does

The classification is cross-site scripting. It refers to the class of defect where input that should have been displayed as plain text is instead interpreted by the browser as a program to run.

The affected area here is the scheduler. JVN's description says arbitrary script may be executed in the web browser of a user logged in to the product. That reads as one of the places where one person types something and other people read it β€” an event title or body β€” being the entry point. However, Cybozu states it is not publishing reproduction steps because doing so could lead to attacks, so exactly which field is involved has not been disclosed.

The severity breakdown makes the character of this flaw clear. The CVSS v4.0 vector is AV:N/AC:L/AT:N/PR:L/UI:A/VC:N/VI:N/VA:N/SC:N/SI:H/SA:N. No confidentiality impact, no availability impact, integrity alone rated high. This is not the kind where data gets siphoned off wholesale; it is rated as the kind where what you see and what you click can be rewritten.

Beyond that, PR:L means the attacker needs a valid login of their own, and UI:A means the victim has to do something for it to work. In other words, this is not a hole anyone on the internet can poke at.

Who goes after this, and what for

Requiring a valid account narrows the field considerably. Realistically, this is for someone who already holds one account inside the organization. An outside attacker who obtained somebody's credentials, a former employee whose account is still alive mid-offboarding, or an external partner invited in as a guest. A low-privilege account is enough.

And what would they do with it? The aim is getting someone with more authority to open that entry, then having actions carried out inside their browser. Garoon is rarely just a calendar; many organizations run their approval and request workflows on it too. Actions firing in an administrator's or approver's session become a way to step over a permission boundary. That the entry point is the company calendar β€” something everyone opens daily β€” does not help.

That said, all of this is contingent on getting that far. There are no reports of exploitation, and no reproduction steps have been published. There is no cause for alarm, and equally no basis for dismissing it as harmless just because only insiders can reach it. Somewhere between those is the right temperature.

The organizations that kept up to date are the ones affected

Here is the odd part. The affected range is 6.17.0 and 6.17.1 β€” the two most recent releases.

Vulnerability stories normally take the shape of "the ones who left it alone are at risk." This is the reverse: organizations that dutifully upgraded each time a release appeared are the ones in scope, while anyone still on 6.16 is not. Something introduced in 6.17.0 was gone again by 6.17.2 β€” a short window in and out.

This shape is not rare. We have covered WordPress plugins where the flaw only existed in the newer release. None of this is an argument for skipping updates β€” the point is that "we're on the latest, so we're fine" holds up just as poorly. Versions have to be checked by number, not by whether you upgraded.

A caveat for anyone on Garoon 5 or earlier

While those versions are out of scope here, one line in Cybozu's bulletin is worth noting separately: no patches will be released for Garoon 5 or earlier.

This flaw only touches the 6.17 line, so Garoon 5 is unaffected today. But it also means no fix will be distributed for those versions no matter what turns up next. Irrelevant now, on the wrong side of the line the next time something appears.

On the risk of running products that no longer receive fixes, we have covered the 78 Sharp printer models that got no firmware and end-of-support Elecom routers. This time you are still on the safe side of it, but it is an occasion to check.

Disclosures for this product come around regularly

This is not the first Garoon advisory. As recently as February 2026, three issues were published together on JVN: cross-site scripting in the mail and message features, plus improper input validation in portal settings. ASCII.jp wrote that one up at the time.

That is not a statement about Garoon's quality. It reflects a structural fact: a web application with many features has many places where input gets displayed, so the same class of defect keeps surfacing. What is more notable is that Cybozu assigns its own CyVDB tracking numbers and has a stated policy of voluntarily publishing anything above a severity threshold to JVN.

No finder is credited on this JVN entry. The wording is that the developer reported it to JPCERT/CC for the purpose of informing users, meaning this came from the vendor rather than from an outside researcher. In the February 2026 batch, one of the three credited Masato Kinugawa by name.

What to check now

If you run the package edition, look at the version number first. If it is 6.17.0 or 6.17.1, move to 6.17.2. No workaround has been offered. There is no configuration change or feature toggle to hold the line with β€” upgrading is the only remedy. Procedures come through your reseller or Cybozu support.

On any other version, there is nothing to do about this one. It is still a reasonable moment to audit accounts, though. Since the flaw requires a valid login, whichever unused accounts are still alive translates directly into how exploitable you are: departed employees, test accounts nobody deleted, logins issued to contractors and never revoked.

Note also that the identifier is not yet registered in the US NVD (it returned "CVE ID Not Found" when checked) and is not on CISA's exploited-vulnerabilities list. Automated vulnerability management tools will not flag this one for the time being. That is a common situation for advisories published through Japan's domestic channel.

Summary

CVE-2026-57279 is a cross-site scripting flaw in the scheduler of Cybozu Garoon. It affects package edition 6.17.0 and 6.17.1 only, and is fixed in 6.17.2. Exploitation requires a valid login plus victim interaction, and none has been reported.

Relative to how well known the product is, the set of organizations this genuinely applies to is narrow. One look at a version number settles it. The more durable takeaways may be the other two: new releases carry new holes, and Garoon 5 and earlier will not receive fixes again.

Frequently asked questions

We use the cloud edition. Do we need to act?

Cybozu's notice covers the package edition and does not mention the cloud edition. Since there is also no statement that the cloud edition is unaffected, we record it as unconfirmed. Contacting Cybozu support is the reliable route if it matters to you.

We are on 6.16. Should we rush to upgrade?

Not on account of this flaw β€” it does not apply. Versions before the 6.17 line may of course be affected by other issues disclosed earlier.

Is there a way to mitigate without upgrading?

No. Cybozu has not offered a workaround; upgrading to 6.17.2 is the only remedy given.

Is it already being exploited?

No exploitation has been reported. Cybozu has not published reproduction steps, and the identifier is not on CISA's exploited-vulnerabilities list.

Sources

avatar-m-1

Makoto Horikawa

Backend Engineer / AWS / Django