Impact
CVE-2026-79572 is an XML External Entity (XXE) vulnerability found in the level-rule module of Distribution Management v1.0.0. Input crafted XML payloads can enable an attacker to read arbitrary files on the server, perform internal network reconnaissance, or trigger further server‑side attacks. As an XXE flaw, the issue allows external entity processing that can expose sensitive configuration files, system data, and potentially allow further attacks if the parser resolves external entities.
Affected Systems
The vulnerability affects the Distribution Management v1.0.0 product, specifically its level-rule module. No other vendor or product lines are documented as affected.
Risk and Exploitability
Based on the description, it is inferred that the likely attack vector is an external attacker sending crafted XML payloads. Although the EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, the nature of the flaw means it is potentially exploitable from a remote system that can send XML to the vulnerable module. With no mitigations in place, an attacker can read confidential data, map internal assets, or launch further attacks. The lack of a publicly available patch or workaround emphasizes the need for immediate remediation.
OpenCVE Enrichment