PatchSiren

Alkacon CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL Alkacon CVE published 2026-05-05

CVE-2026-38429

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature. This issue arises from insecure XML parsing of user-supplied .zip files containing a manifest.xml. The vulnerability has been assigned a CVSS score of 9.8, indicating critical severity. Affected product deployments should be reviewed for exposure, and owners should be assigned for follow-up. The vulnerability [truncated]