HIGH
datavane
CVE published 2026-08-14
CVE-2026-69101
CVE-2026-69101 is an XML external entity (XXE) injection vulnerability in Datavane TIS v5.0.0 that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration. The vulnerability exists in the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can exploit this vulnera [truncated]