CVE-2026-82578
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Sep 11, 2026
Vendor
unknown
Description
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.