CVE-2026-38429: n/a
OpenCMS versions 20 and earlier contain a critical XML External Entity (XXE) vulnerability in the Admin Import DB feature. This flaw arises from insecure XML parsing of user-supplied . zip files that include a manifest.xml, allowing an attacker to potentially execute arbitrary code or access sensitive data. The vulnerability has a CVSS score of 9.8, indicating a critical severity with high impact on confidentiality, integrity, and availability. No official patch or remediation guidance has been provided yet, and no known exploits are reported in the wild. Users should monitor vendor advisories for updates and avoid importing untrusted . zip files until a fix is available.
AI Analysis
Technical Summary
CVE-2026-38429 is a critical XML External Entity (XXE) vulnerability affecting OpenCMS version 20 and earlier. The vulnerability exists in the Admin Import DB feature due to insecure parsing of XML data within user-supplied .zip files containing a manifest.xml. Exploitation could lead to disclosure of sensitive information, system compromise, or denial of service. The CVSS v3.1 base score is 9.8, reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. No patch or official remediation level has been disclosed, and the product is not a cloud service, so remediation depends on vendor updates or user mitigation.
Potential Impact
Successful exploitation of this XXE vulnerability can lead to full compromise of the affected system, including unauthorized disclosure of sensitive data, modification of system data, and denial of service. The critical CVSS score (9.8) reflects the potential for complete system takeover without requiring authentication or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid importing untrusted .zip files containing XML data into the Admin Import DB feature. Implement network-level protections to restrict access to the administrative interface and consider disabling the vulnerable feature if feasible.
CVE-2026-38429: n/a
Description
OpenCMS versions 20 and earlier contain a critical XML External Entity (XXE) vulnerability in the Admin Import DB feature. This flaw arises from insecure XML parsing of user-supplied . zip files that include a manifest.xml, allowing an attacker to potentially execute arbitrary code or access sensitive data. The vulnerability has a CVSS score of 9.8, indicating a critical severity with high impact on confidentiality, integrity, and availability. No official patch or remediation guidance has been provided yet, and no known exploits are reported in the wild. Users should monitor vendor advisories for updates and avoid importing untrusted . zip files until a fix is available.
CVSS v3.1
Score 9.8critical
Affected software
pkg:github/alkacon/opencms-coreRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-38429 is a critical XML External Entity (XXE) vulnerability affecting OpenCMS version 20 and earlier. The vulnerability exists in the Admin Import DB feature due to insecure parsing of XML data within user-supplied .zip files containing a manifest.xml. Exploitation could lead to disclosure of sensitive information, system compromise, or denial of service. The CVSS v3.1 base score is 9.8, reflecting network attack vector, low attack complexity, no privileges required, no user interaction, and high impact on confidentiality, integrity, and availability. No patch or official remediation level has been disclosed, and the product is not a cloud service, so remediation depends on vendor updates or user mitigation.
Potential Impact
Successful exploitation of this XXE vulnerability can lead to full compromise of the affected system, including unauthorized disclosure of sensitive data, modification of system data, and denial of service. The critical CVSS score (9.8) reflects the potential for complete system takeover without requiring authentication or user interaction.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, avoid importing untrusted .zip files containing XML data into the Admin Import DB feature. Implement network-level protections to restrict access to the administrative interface and consider disabling the vulnerable feature if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-04-06T00:00:00.000Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 69fa200ecbff5d861012a7b5
Added to database: 05/05/2026, 16:51:26 UTC
Last enriched: 05/13/2026, 03:44:50 UTC
Last updated: 08/02/2026, 07:17:57 UTC
Views: 147
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.