Description
Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container.

This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Published: 2026-09-08
Score: 7.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Improper restriction of XML external entity references in Hitachi Cosminexus Component Container enables attackers to pass crafted XML that references external entities. This flaw can allow the application to read arbitrary files, retrieve data from remote resources, or potentially trigger code execution if the external entities are exploited in a more complex environment. The impact is primarily the disclosure of confidential data, but in some configurations could facilitate further attack stages.

Affected Systems

Hitachi Cosminexus Component Container versions 11‑70‑01 to 11‑70‑02, 11‑60‑01 to 11‑60‑02, 11‑50‑01 to 11‑50‑03, 11‑40‑01 to 11‑40‑03, 11‑30‑01 to 11‑30‑08, 11‑20‑01 to 11‑20‑09, 11‑10‑01 to 11‑10‑11, 11‑00‑01 to 11‑00‑12, 09‑87‑01 to 09‑87‑09, 09‑80‑01 to 09‑80‑04, 09‑70‑01 to 09‑70‑27, 09‑50‑01 to 09‑50‑22, and 09‑00‑01 to 09‑00‑18.

Risk and Exploitability

The CVSS score of 7.4 classifies this as high severity. The EPSS score is not available, and it is not listed in the CISA KEV catalog. The likely attack vector is inferred to be through any interface that accepts XML input—such as web services, configuration files, or management consoles—allowing an adversary to inject malicious XML. Exploitation would require authentication or access to the vulnerable component; therefore, internal attackers or those who can send crafted XML are the most realistic threat actors.

Generated by OpenCVE AI on September 8, 2026 at 09:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Cosminexus Component Container to version 11‑70‑03 or newer, which removes the XML external entity vulnerability.
  • If an upgrade is not immediately possible, reconfigure the XML parser to disallow external entities or use a library that automatically disables them.
  • Validate the configuration by submitting test XML containing external entities and confirming the parser rejects the input; monitor logs for any attempts to process external entity references.

Generated by OpenCVE AI on September 8, 2026 at 09:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Hitachi
Hitachi cosminexus Component Container
Vendors & Products Hitachi
Hitachi cosminexus Component Container

Tue, 08 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Title XXE Vulnerability in Cosminexus Component Container
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 7.4, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H'}


Subscriptions

Hitachi Cosminexus Component Container
cve-icon MITRE

Status: PUBLISHED

Assigner: Hitachi

Published:

Updated: 2026-09-08T07:56:36.056Z

Reserved: 2026-08-06T08:05:05.247Z

Link: CVE-2026-71375

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-08T08:17:11.707

Modified: 2026-09-08T08:17:11.707

Link: CVE-2026-71375

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T10:00:08Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference