Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Datavane
Datavane tis |
|
| Vendors & Products |
Datavane
Datavane tis |
Fri, 14 Aug 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a malicious XML document containing an external DTD reference to the edit_workflow action, causing the server to issue outbound HTTP requests to attacker-controlled infrastructure and exfiltrate local files readable by the TIS process user, including configuration files and Derby database credentials. | |
| Title | Datavane TIS v5.0.0 XXE Injection via doEditWorkflow Endpoint | |
| Weaknesses | CWE-611 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T14:33:17.021Z
Reserved: 2026-08-03T10:44:14.336Z
Link: CVE-2026-69101
No data.
Status : Received
Published: 2026-08-14T15:17:10.053
Modified: 2026-08-14T15:17:10.053
Link: CVE-2026-69101
No data.
OpenCVE Enrichment
Updated: 2026-08-14T15:30:03Z