Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 14 Sep 2026 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external entities in BPMN files to read arbitrary local files or trigger requests to internal network endpoints when diagram layout is computed. | |
| Title | Flowable flowable-engine through 8.0.0 XXE via ProcessDiagramLayoutFactory | |
| Weaknesses | CWE-611 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-14T22:10:55.214Z
Reserved: 2026-09-14T21:55:42.613Z
Link: CVE-2026-91197
No data.
Status : Received
Published: 2026-09-14T23:19:00.173
Modified: 2026-09-14T23:19:00.173
Link: CVE-2026-91197
No data.
OpenCVE Enrichment
No data.
-
CWE-611
Improper Restriction of XML External Entity Reference