EIP-2026-119672
PRE-CVECyberPower Systems PowerPanel 3.1.2 - XML External Entity Out-Of-Band Data Retrieval
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-119672. PoCs published by LiquidWorm.
AI-analyzed exploit summary This exploit demonstrates an unauthenticated XML External Entity (XXE) vulnerability in CyberPower Systems PowerPanel Business Edition 3.1.2. The vulnerability allows arbitrary file retrieval via out-of-band (OOB) data exfiltration by leveraging DTD parameter entities in the XML parsing logic of the `xmlservice` servlet.
Description
CyberPower Systems PowerPanel 3.1.2 - XML External Entity Out-Of-Band Data Retrieval
Exploits (1)
This exploit demonstrates an unauthenticated XML External Entity (XXE) vulnerability in CyberPower Systems PowerPanel Business Edition 3.1.2. The vulnerability allows arbitrary file retrieval via out-of-band (OOB) data exfiltration by leveraging DTD parameter entities in the XML parsing logic of the `xmlservice` servlet.