Description
XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.
Published: 2026-09-03
Score: 6.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch Now
AI Analysis

Impact

XG VisionTerminal and XG-X VisionTerminal units from Keyence Corporation lack adequate protection against XML External Entity references. When a user opens a specially crafted setting file, the application processes the XML in a way that allows external resources to be accessed, permitting the disclosure of sensitive information stored on the host system. This vulnerability is an XML External Entity (XXE) flaw, recorded as CWE‑611.

Affected Systems

The affected devices are Keyence Corporation’s XG VisionTerminal and XG-X VisionTerminal. The advisory does not list any specific firmware or software version, indicating that all current installations may be vulnerable until a patch is released.

Risk and Exploitability

The CVSS score is 6.7, indicating a moderate likelihood of exploitation that could result in confidential data exposure. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw is triggered by parsing a vulnerable XML setting file, the attack vector is most likely local or requires the attacker to supply a file to the device, such as through an administrative interface or file transfer. If the device accepts externally supplied setting files, a remote attacker might exploit the XXE to read system files.

Generated by OpenCVE AI on September 3, 2026 at 15:09 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install any firmware or software update from Keyence that disables XML external entity processing in setting files.
  • If an update is not available, configure the device to reject or ignore XML external entity references within setting files, or disable XML parsing of setting files entirely.
  • Limit access to the creation and modification of setting files so that only trusted administrators can write them, preventing untrusted users from providing malicious content.
  • Verify that your environment does not allow untrusted XML files to be loaded by XG VisionTerminal, and consider restricting the device’s file permissions to prevent access to sensitive system files.

Generated by OpenCVE AI on September 3, 2026 at 15:09 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 03 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Keyence Corporation
Keyence Corporation xg-x Visionterminal
Keyence Corporation xg Visionterminal
Vendors & Products Keyence Corporation
Keyence Corporation xg-x Visionterminal
Keyence Corporation xg Visionterminal

Thu, 03 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Title XXE Vulnerability in Keyence XG VisionTerminal Settings Causes Information Disclosure

Thu, 03 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 13:00:00 +0000

Type Values Removed Values Added
Description XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 6.7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Keyence Corporation Xg-x Visionterminal Xg Visionterminal
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-09-15T11:32:05.573Z

Reserved: 2026-08-31T11:06:31.707Z

Link: CVE-2026-82918

cve-icon Vulnrichment

Updated: 2026-09-03T13:11:49.072Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T13:06:15.910

Modified: 2026-09-15T12:17:53.467

Link: CVE-2026-82918

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T15:32:57Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference