PT-2026-97035 · Mpxj · Mpxj

CVE-2026-61570

·

Published

2026-09-22

·

Updated

2026-09-24

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MPXJ versions 5.5.5 through 16.4.0
Description When parsing XML from the ZTIMEINTERVALS column of a Merlin project SQLite database, the software creates a DocumentBuilder with default settings that leave doctype declarations and external entities enabled. This allows a crafted database to trigger the parser to read an arbitrary local file, although the subsequent processing of the parsed XML makes the disclosure of the file contents unlikely.
Recommendations Update to version 16.4.1. Avoid reading Merlin project files. Only accept Merlin project files from trusted sources. Preprocess Merlin SQLite databases to strip doctype declarations from the ZTIMEINTERVALS column.

Exploit

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-61570
GHSA-5VVX-3H34-F3GJ

Affected Products

Mpxj