PT-2026-35811 · Unknown · Grassmarlin

Grady Derosa

·

Published

2026-04-28

·

Updated

2026-05-28

·

CVE-2026-6807

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GRASSMARLIN versions prior to 3.2.1 GRASSMARLIN version 3.2.1
Description Improper handling of XML input occurs due to insufficient hardening of the XML parsing process. This allows crafted session data, specifically within session files (.gm3), to trigger XML External Entity (XXE) injection—a technique where an application processes external entities within an XML document to access unauthorized data. This flaw can lead to the unintended exposure of sensitive information, including the extraction of credentials and arbitrary documents such as SSH keys, which may facilitate lateral movement within industrial networks.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2026-6807

Affected Products

Grassmarlin