PT-2026-68723 · Unknown · Schemavalidator Mediator
CVE-2026-3415
·
Published
2026-08-06
·
Updated
2026-08-31
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
SchemaValidator Mediator (affected versions not specified)
Description
The XML and schema validation functionalities within the SchemaValidator Mediator process XML input as part of validation flows. Under certain conditions, the XML parser allows the resolution of external entities when handling user-supplied XML content. This occurs when an attacker with sufficient privileges provides crafted XML payloads to the mediator flows. This can lead to the unauthorized reading of files on the hosting server, the triggering of outbound requests to unintended internal or external locations, or excessive resource consumption during parsing, which may impact product availability.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XML Entity Expansion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Schemavalidator Mediator