CVE-2026-4374

CRITICAL

RTI Connext Professional Multiple Services - XXE

Title source: manual
STIX 2.1

Description

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup.<p>This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.1.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.</p>

References (1)

Core 1

Scores

CVSS v3 9.1
EPSS 0.0024
EPSS Percentile 14.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (7)
RTI/Connext Professional 5.3.0 - 5.3.*
RTI/Connext Professional 6.0.0 - 6.0.*
RTI/Connext Professional 6.1.0 - 6.1.*
RTI/Connext Professional 6.1.0 - 6.1.2.34
RTI/Connext Professional 7.1.0 - 7.3.1.1
RTI/Connext Professional 7.4.0 - 7.7.0
rti/connext_professional 5.3.0 - 5.3.1.45
Published Apr 01, 2026
Tracked Since Apr 01, 2026