Newell Brands · Dymo Id · CVE-2026-101893
**Name of the Vulnerable Software and Affected Versions**
Newell Brands DYMO ID versions prior to 1.6.0
**Description**
The software parses job files using the `XmlDocument.Load()` function without disabling Document Type Definition (DTD) processing. The PC Job Files view automatically parses all recognized job file extensions during folder browsing. An attacker can use a specially crafted file on a browsed network share to perform Server-Side Request Forgery (SSRF), capture NTLMv2 credentials, read local files, or cause the process to crash.
**Recommendations**
Update Newell Brands DYMO ID to version 1.6.0.