Sceawere

Vulnerability Detail

CVE-2026-69101UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Datavane TIS XML External Entity Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.7
Creation Date
3h ago
Vendor
datavane
Product
tis
Attack Type
Improper Restriction of XML External Entity Reference
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration by supplying a crafted taskScript payload to the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can send a malicious XML document containing an external DTD reference to the edit_workflow action, causing the server to issue outbound HTTP requests to attacker-controlled infrastructure and exfiltrate local files readable by the TIS process user, including configuration files and Derby database credentials.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.7",
  "pubDate": "2026-08-14T15:17:10.053Z",
  "pubdate": "2026-08-14T15:17:10.053Z",
  "executiveSummary": "Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that enables authenticated attackers to execute server-side request forgery (SSRF) and perform out-of-band file exfiltration. The vulnerability exists because the application processes XML input through an insecurely configured XML parser.\nThe primary impact includes the unauthorized disclosure of sensitive local system files readable by the TIS process user, such as configuration files and Derby database credentials. Attackers leverage this flaw to interact with internal or external resources via outbound HTTP requests initiated by the server.\nExploitation requires authentication and the ability to interact with the target application endpoint. The risk implications are severe due to the potential exposure of sensitive credentials and internal network access, allowing attackers to escalate their foothold within the affected environment.",
  "technicalDetails": "The vulnerability resides in the workflow editing functionality of Datavane TIS v5.0.0, specifically within the edit_workflow action and the doEditWorkflow endpoint. The root cause is the improper configuration of the XML parsing mechanism, which utilizes an unhardened DocumentBuilderFactory with external entities and Document Type Definition (DTD) loading explicitly enabled.\nAn authenticated attacker initiates the attack flow by supplying a crafted taskScript payload containing a malicious XML document. This payload includes an external DTD reference designed to exploit the insecure XML parser configuration. When the vulnerable doEditWorkflow endpoint processes the supplied XML, the underlying parser resolves the external entities and DTD references.\nThis behavior forces the server to issue outbound HTTP requests to attacker-controlled infrastructure, facilitating server-side request forgery (SSRF). Furthermore, the parser reads local files accessible to the permissions of the TIS process user and transmits the file contents out-of-band to the attacker via the external DTD mechanism.\nPost-exploitation impact includes the potential exfiltration of critical system assets, including application configuration files and Derby database credentials. The attack requires authenticated access to the target application, but leverages the inherent trust of the server-side XML parser to bypass network segmentation and access internal or restricted resources."
}
CVE-2026-69101: Datavane TIS XML External Entity Vulnerability (HIGH Severity, CVSS: 7.7) - Sceawere