Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-82578

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Sep 11, 2026
Vendor unknown

Description

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.

References