Vulnary
← back to the feed
Critical· 9.8

CVE-2026-38429

OpenCMS versions 20 and earlier are vulnerable to an XML External Entity (XXE) flaw in the Admin Import DB feature. By uploading a specially crafted .zip file that contains a malicious manifest.xml, an attacker can read arbitrary files, execute code, or cause a denial‑of‑service. The flaw can be triggered remotely without authentication.

publishedMay 5, 2026
last modifiedJul 24, 2026
sourcesNVD
severity · cvss
9.8
critical · how bad it is
exploitation · epss
<1%
22th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 7, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

OpenCMS v20 and earlier, specifically the Admin Import DB feature that processes user‑supplied .zip files containing a manifest.xml.

02

Real-world impact

An attacker could read sensitive files on the server, execute arbitrary code with the privileges of the web application, or crash the system by uploading a malicious .zip file to the Admin Import DB feature.

03

Why this severity

The CVSS score of 9.8 reflects that the vulnerability is remotely exploitable with no authentication, can lead to full compromise of confidentiality, integrity, and availability, and requires only low effort to exploit.

04

What to do about it

no official fix yet
interim mitigations
  • Avoid uploading untrusted .zip files to the Admin Import DB feature.
  • Disable the Admin Import DB feature if it is not needed.
  • Use a secure XML parser that disallows external entities when processing XML files.
  • Apply any future patches or updates from the vendor as soon as they are released.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

  1. May 5, 2026 · May 5, 2026
    Published
    Disclosed and added to the National Vulnerability Database.
  2. Jul 24, 2026 · 11d ago
    Advisory updated
    The NVD record was last revised.
06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionNone needed
ScopeUnchanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →