Description
OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.
Published: 2026-05-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

OpenCMS versions 20 and earlier are affected by an XML External Entity (XXE) flaw in the Admin Import DB feature. The vulnerability arises because the application insecurely parses XML contained within user‑supplied ZIP files that include a manifest.xml. An attacker who can supply a crafted ZIP file can cause the server to resolve external entities, potentially allowing the read of arbitrary files on the system or otherwise exfiltrating sensitive data. The impact is limited to information disclosure, though in vulnerable configurations it could lead to denial of service if the parser is overwhelmed by large or malformed external entities.

Affected Systems

The affected product is OpenCMS, release 20 and any prior versions. No specific sub‑product or module is listed beyond the core CMS application.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in CISA's KEV catalog. The CVSS score is not provided, but the attack vector is remote and requires an application‑level interaction: the attacker must upload a malicious ZIP file through the Admin Import DB interface, which is typically restricted to administrators. Because the flaw is accessed via the web interface, exploitation is feasible from anywhere with network access to the CMS server. The risk level is moderate to high for environments where the Admin Import DB feature is enabled and accessible to guest or untrusted users.

Generated by OpenCVE AI on May 5, 2026 at 18:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to OpenCMS 21 or later, if a newer release is available.
  • If an upgrade is not possible, disable or restrict the Admin Import DB feature to a narrow set of trusted administrators.
  • Configure the XML parser to disallow entity resolution or replace it with a safe parser that blocks external entities.
  • Apply any vendor security patches or hotfixes as soon as they are released.
  • Monitor server logs for unusual ZIP upload activity and add IDS rules for malformed XML.

Generated by OpenCVE AI on May 5, 2026 at 18:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 05 May 2026 18:45:00 +0000

Type Values Removed Values Added
Title XML External Entity (XXE) Vulnerability in OpenCMS Admin Import DB Feature
First Time appeared Alkacon
Alkacon opencms
Weaknesses CWE-611
Vendors & Products Alkacon
Alkacon opencms

Tue, 05 May 2026 17:00:00 +0000

Type Values Removed Values Added
Description OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-05-05T16:30:08.697Z

Reserved: 2026-04-06T00:00:00.000Z

Link: CVE-2026-38429

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-05-05T17:17:04.547

Modified: 2026-05-05T20:24:04.853

Link: CVE-2026-38429

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-05T18:30:29Z

Weaknesses