PT-2026-37087 · Opencms · Opencms
Westenberger
·
Published
2026-05-05
·
Updated
2026-05-12
·
CVE-2026-38429
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
OpenCMS versions prior to 21
Description
The Admin Import DB feature is susceptible to XML External Entity (XXE), a flaw where an application processes XML input containing a reference to an external entity, potentially allowing unauthorized access to files or internal systems. This occurs due to insecure XML parsing of user-supplied .zip files that contain a
manifest.xml file.Recommendations
Update to a version later than v20.
As a temporary workaround, restrict the use of the Admin Import DB feature or avoid importing .zip files from untrusted sources.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opencms