PatchSiren

datavane CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH datavane CVE published 2026-08-14

CVE-2026-69101

CVE-2026-69101 is an XML external entity (XXE) injection vulnerability in Datavane TIS v5.0.0 that allows authenticated attackers to perform server-side request forgery and out-of-band file exfiltration. The vulnerability exists in the doEditWorkflow endpoint, which processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Attackers can exploit this vulnera [truncated]