Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external entities in BPMN files to read arbitrary local files or trigger requests to internal network endpoints when diagram layout is computed.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 23:19
Updated : 2026-09-14 23:19
NVD link : CVE-2026-91197
Mitre link : CVE-2026-91197
CVE.ORG link : CVE-2026-91197
JSON object : View
Products Affected
No product.
CWE
CWE-611
Improper Restriction of XML External Entity Reference
