XML External Entity Injection in NanoXML by Thales
CVE-2026-19614

5.3MEDIUM

Key Information:

Vendor

Cyberelf

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-19614?

The XML parsing mechanism in NanoXML version 2.2.3 is susceptible to XML External Entity (XXE) injection attacks. By default, the support for XML external entities is enabled, which could allow attackers to exploit this vulnerability for various attacks. This may lead to unauthorized access to sensitive data and enable other security risks, showcasing the importance of applying security patches and configurations to mitigate potential threats.

Affected Version(s)

NanoXML 2.2.3

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dominique RIGHETTO
.