Description
Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external entities in BPMN files to read arbitrary local files or trigger requests to internal network endpoints when diagram layout is computed.
Published: 2026-09-14
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Local File Disclosure and Internal Network Exposure
Action: Apply Patch
AI Analysis

Impact

The vulnerability resides in the of the Flowable engine, where external entity resolution is not disabled during XML parsing of BPMN resources. This omission allows an attacker who has permission to deploy processes to embed a DOCTYPE declaration with malicious external entities is computed, the attacker can read arbitrary local files or force the engine to make network requests to internal endpoints, exposing sensitive system information.

Affected Systems

Flowable flowable-engine versions up to and including 8.0.0 are vulnerable. The issue affects deployments of the Flowable process engine used in Java applications that parse BPMN XML. The vulnerability originates in ProcessDiagramLayoutFactory within the engine’s diagram package.

Risk and Exploitability

The CVSS score of 7.1 indicates a moderate to high severity. The EPSS score of < 1% indicates a very low exploitation probability, though the vulnerability remains usable by actors with deployment privileges. The vulnerability is not listed in CISA KEV, implying no known widespread exploitation yet. The attack vector requires compromising process deployment permissions to trigger data exposure if application deployment endpoints are exposed to an untrusted user base.

Generated by OpenCVE AI on September 17, 2026 at 19:01 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Flowable flowable-engine to a version released after 8.0.0 that contains the fix for the external entity processing flaw.
  • Restrict deployment privileges by ensuring only trusted administrators can upload or deploy BPMN process definitions, and enforce strict role‑based access control on the deployment APIs that rejects BPMN XML files containing DOCTYPE declarations or external entity references, thereby blocking the exploitation path.
  • Configure the Flowable engine to disable external entity resolution globally, for example by setting the XML parser feature 'http://apache.org/xml/features/disallow-doctype-decl' to true or disabling the ‘external entity resolver’ in the ProcessDiagramLayoutFactory configuration, to prevent any deserialization of malicious DOCTYPEs when no patch is applied.

Generated by OpenCVE AI on September 17, 2026 at 19:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Flowable
Flowable flowable-engine
Vendors & Products Flowable
Flowable flowable-engine

Wed, 16 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Description Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external entities in BPMN files to read arbitrary local files or trigger requests to internal network endpoints when diagram layout is computed.
Title Flowable flowable-engine through 8.0.0 XXE via ProcessDiagramLayoutFactory
Weaknesses CWE-611
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Flowable Flowable-engine
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:22:14.221Z

Reserved: 2026-09-14T21:55:42.613Z

Link: CVE-2026-91197

cve-icon Vulnrichment

Updated: 2026-09-16T16:24:39.627Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T23:19:00.173

Modified: 2026-09-24T20:44:42.207

Link: CVE-2026-91197

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:30:18Z

Weaknesses
  • CWE-611

    Improper Restriction of XML External Entity Reference