PT-2026-22315 · Xerox · Xerox Freeflow Core

Published

2026-02-27

·

Updated

2026-03-04

·

CVE-2026-2252

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Xerox FreeFlow Core versions up to and including 8.0.7
Description An XML External Entity (XXE) issue allows a malicious user to perform Server-Side Request Forgery (SSRF) by submitting specially crafted XML input that includes malicious external entity references. This allows an attacker to potentially make requests to internal or external resources on behalf of the server.
Recommendations Upgrade to Xerox FreeFlow Core version 8.1.0.

Fix

XXE

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-2252

Affected Products

Xerox Freeflow Core