Back to overview

CVE-2026-38429

CRITICAL
9.8
CVSS 3.1
Description
OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

Metadata

CVE ID
CVE-2026-38429
State
PUBLISHED
Assigner
mitre
Reserved
2026-04-06 00:00 UTC
Published
2026-05-05 00:00 UTC
Last updated
2026-05-06 18:40 UTC
Primary CWE
CWE-611
CWE-611 Improper Restriction of XML External Entity Referenc…
Vendor / Product
n/a / n/a
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
n/a n/a n/a
Weakness (CWE)
CWESourceDescription
cna n/a
CWE-611 adp CWE-611 Improper Restriction of XML External Entity Reference
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 adp CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview