PT-2026-72029 · Datavane+1 · Tis

·

CVE-2026-69101

·

Published

2026-08-14

·

Updated

2026-08-14

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Datavane TIS version 5.0.0
Description An XML external entity (XXE) injection exists when the software processes XML through an unhardened DocumentBuilderFactory with external entities and DTD loading enabled. Authenticated attackers can exploit this by supplying a crafted taskScript payload to the 'doEditWorkflow' endpoint. This allows for server-side request forgery (SSRF), where the server is forced to make outbound HTTP requests to attacker-controlled infrastructure, and out-of-band file exfiltration of local files readable by the TIS process user, such as configuration files and Derby database credentials.
Recommendations Update Datavane TIS version 5.0.0 to a version where the DocumentBuilderFactory is hardened to disable external entities and DTD loading.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-69101

Affected Products

Tis