CVE-2026-51080
A vulnerability has been identified in the libpvestorage-perl and libpve-storage-perl software libraries. This flaw is an XML External Entity (XXE) vulnerability, which occurs when an application processes XML data containing references to external entities.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of libpvestorage-perl version 9.1.1 and libpve-storage-perl version 8.3.7.
Real-world impact
An attacker could potentially exploit this flaw to access unauthorized data or interact with internal systems through the XML processing mechanism.
Why this severity
The critical score reflects that the vulnerability can be exploited remotely over a network without requiring any user interaction or special privileges.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
NVD description