Improper XML External Entity Handling in Cosminexus Component Container
CVE-2026-71375

7.4HIGH

Key Information:

Vendor

Hitachi

Vendor
CVE Published:
8 September 2026

What is CVE-2026-71375?

A vulnerability exists in the Cosminexus Component Container due to improper handling of XML external entity references. This flaw could allow an attacker to exploit the system by sending specially crafted XML documents, potentially causing data disclosure or other malicious activities. The affected versions span various releases, creating a significant security risk for users who have not updated to the patched versions.

Affected Version(s)

Cosminexus Component Container Windows 11-70-01 < 11-70-03

Cosminexus Component Container Windows 11-60 < 11-60-03

Cosminexus Component Container Windows 11-50 <= 11-50-03

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.