CVE-2026-8045
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side fi
CVSS
6.5
Medium
EPSS
0.2%
p14
KEV
—
Exploit Today
4
0-100
Published: Jun 9, 2026 · Last modified: Jul 20, 2026 · CWE-611
0.2%EPSS · 30 days0.2%
2026-07-282026-08-24
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-765724.7 MED25.9%
——8A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _transformPHP of the file classes/xslt/XSLTransformer.php. The manipulation results in xml external entity reference. The attack can be executed remotely. Upgrading to version 3.3.0-23, 3.4.0-11 and 3.5.0-5 is sufficient to fix this issue. The patch is identified as 78c699370ea43ae2784e1c4ace7c947d207f2b47. Upgrading the affected component is advised.6dCVE-2026-203207.5 HIG31.3%
——9A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system.
This vulnerability exists because XML entries are improperly parsed due to external entity resolution being allowed by default. An attacker could exploit this vulnerability by sending a crafted XML message to the Open Client Interface – Provisioning (OCI-P) service. A successful exploit could allow the attacker to view sensitive files from the filesystem with the privileges of the Cisco BroadWorks user.6dCVE-2026-672686.5 MED1.1%
——0Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery.5dCVE-2026-704236.5 MED19.6%
——6Dell OpenManage Enterprise, versions prior to 4.7.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure.5dCVE-2026-750585.5 MED2.0%
——1In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers9dCVE-2026-750555.5 MED2.0%
——1In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE9d