CVE-2026-82578

When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-11 15:17

Updated : 2026-09-11 15:17


NVD link : CVE-2026-82578

Mitre link : CVE-2026-82578

CVE.ORG link : CVE-2026-82578


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference