Impact
CVE-2026-79572 is an XML External Entity (XXE) vulnerability in the level‑rule module of Distribution Management v1.0.0. The flaw permits attackers to craft XML payloads that are processed by the server’s XML parser, enabling the reading of arbitrary files on the host, internal network reconnaissance, or the initiation of additional server‑side attacks. As a typical XXE issue, the weakness can expose confidential configuration data and system files.
Affected Systems
The only documented affected product is the Distribution Management v1.0.0 level‑rule module; no other vendor or product line is listed as impacted.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.5, indicating high severity, and an EPSS score of less than 1 %, suggesting a low probability of exploitation at the time of analysis. It is not listed in the CISA KEV catalog, but because an attacker can send XML to the vulnerable endpoint, remote exploitation is feasible. In the absence of an official fix or workaround, an attacker who can reach the module can read sensitive files, map internal assets, or attempt further attacks on the host.
OpenCVE Enrichment