CVE-2026-82578
EUVD-2026-7611711.09.2026, 15:17
When XML batch processing is turned on and the XPath option is selected, the raw batch input goes through a default XPath/JAXP setup with no entity restrictions, so XXE injection can allow data exfiltration and denial-of-service attacks.Enginsight
Awaiting analysis
This vulnerability is currently awaiting analysis.