CVE-2026-40042
Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, comments, and wiki articles to trigger entity resolution via simplexml_load_string() without LIBXML_NONET restrictions.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.37%
- CWE
- CWE-403
- Published
- 2026-04-13
- Last modified
- 2026-05-12
Affected products
- pancho Pachno
- Pachno Pachno
Weakness type
Related vulnerabilities
- CVE-2026-33263 — When mail_max_userip_connections is set (default 10) and reached, submission-login can crash with...
- CVE-2026-16526 — Pcp: pcp: privilege escalation to root via linux_sockets pmda vulnerability
- CVE-2025-15114 — Ksenia Security lares Home Automation 1.6 PIN Exposure Vulnerability
- CVE-2024-58280 — CMSimple 5.15 Remote Command Execution via Extensions Configuration
- CVE-2024-21626 — runc container breakout through process.cwd trickery and leaked fds