Vulnerable XML Parsing in Newell Brands DYMO ID Product
CVE-2026-101893
5.1MEDIUM
What is CVE-2026-101893?
The Newell Brands DYMO ID version 1.5.1.71 contains a vulnerability that arises from the parsing of job files without disabling DTD processing in XmlDocument.Load(). As a result, any crafted job file placed in browsed network shares can be exploited to perform server-side request forgery (SSRF), potentially capture NTLMv2 credentials, read local files, or even crash the application. This issue was addressed in version 1.6.0 with appropriate fixes implemented.
Affected Version(s)
DYMO ID 1.5.1.71 < 1.6.0
DYMO ID 1.6.0
References
CVSS V4
Score:
5.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Paweł Karwowski, GetResponse S.A.
Bartosz Nowicki, GetResponse S.A.
