CVE-2026-38429

CRITICAL

OpenCMS v20 - XML External Entity Injection

Title source: manual
STIX 2.1

Description

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

Scores

CVSS v3 9.8
EPSS 0.0030
EPSS Percentile 21.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-611
Status published
Published May 05, 2026
Tracked Since May 05, 2026