PatchSiren cyber security CVE debrief
CVE-2026-39053 Oinone CVE debrief
CVE-2026-39053 documents an XML External Entity (XXE) vulnerability in Oinone Pamirs 7.0.0, published by NVD on 2026-05-15 and last modified on 2026-05-18. The issue resides in XStream-based XML parsing logic, where attacker-controlled XML passed to framework entry points such as PamirsXmlUtils.fromXML(...) or ViewXmlUtils.fromXML(...) can trigger unsafe XML processing. Successful exploitation may result in file disclosure or Server-Side Request Forgery (SSRF). The vulnerability is rated CVSS 3.1 6.5 (MEDIUM) with vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L. NVD lists the vulnerability status as Deferred. No Known Exploited Vulnerabilities (KEV) entry exists. The vendor field is marked low-confidence and flagged for review, with Oinone identified as a candidate based on reference domain analysis.
- Vendor
- Oinone
- Product
- Pamirs
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-15
- Original CVE updated
- 2026-05-18
- Advisory published
- 2026-05-15
- Advisory updated
- 2026-05-18
Who should care
Organizations running Oinone Pamirs 7.0.0 applications that process XML input from untrusted sources; security teams responsible for XXE and SSRF prevention; developers maintaining applications using XStream for XML deserialization.
Technical summary
The vulnerability exists in Oinone Pamirs 7.0.0's XStream-based XML parsing implementation. When untrusted XML is processed through PamirsXmlUtils.fromXML(...) or ViewXmlUtils.fromXML(...), the parser resolves external entities without adequate restrictions. This allows attackers to reference external DTDs or entities, potentially reading arbitrary files from the server filesystem or initiating requests to internal/external systems (SSRF). The CVSS 3.1 score of 6.5 reflects network accessibility, low attack complexity, and no required privileges or user interaction, with limited confidentiality impact and low availability impact.
Defensive priority
medium
Recommended defensive actions
- Review application code for usage of PamirsXmlUtils.fromXML and ViewXmlUtils.fromXML methods
- Upgrade XStream to a version with secure-by-default XML parsing or explicitly disable external entity processing
- Implement input validation and restrict XML parsing to expected schemas
- Monitor Oinone Pamirs changelog and security advisories for patched versions
- Conduct security review of XML deserialization endpoints for SSRF and file disclosure risks
Evidence notes
The CVE description identifies specific vulnerable methods (PamirsXmlUtils.fromXML, ViewXmlUtils.fromXML) and the underlying XStream library as the XXE vector. CVSS scoring and CWE-611 classification are sourced from official NVD metadata. Vendor attribution is preliminary based on reference domain candidate matching and requires verification.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-39053 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-39053
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-39053 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-39053
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://gist.github.com/Misakim1/859c3eb9ced699089ee0747dae9bedc1
-
Source reference
Unverified legacy reference
URL: https://github.com/oinone/oinone-pamirs
-
Source reference
Unverified legacy reference
URL: https://www.oinone.top/changelog
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.