CVE-2026-91197
Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external entities in BPMN files to read arbitrary local files or trigger requests to internal network endpoints when diagram layout is computed.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-611
- Published
- 2026-09-14
- Last modified
- 2026-09-16
Affected products
- flowable flowable-engine
Weakness type
Related vulnerabilities
- CVE-2025-58360 — GeoServer is vulnerable to an Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
- CVE-2025-2776 — SysAid On-Prem <= 23.3.40 serverurl Proceessing XML External Entity Injection
- CVE-2025-2775 — SysAid On-Prem <= 23.3.40 Checkin Proceessing XML External Entity Injection
- CVE-2025-68493 — Apache Struts, Apache Struts: XXE vulnerability in outdated XWork component
- CVE-2025-11700 — N-central Multiple XXE Injection Vulnerabilities
- CVE-2025-2777 — SysAid On-Prem <= 23.3.40 lshw Proceessing XML External Entity Injection
- CVE-2025-30220 — GeoTools, GeoServer, and GeoNetwork XML External Entity (XXE) Processing Vulnerability in XSD schema handling
- CVE-2026-32251 — Tolgee has an XXE Injection in Translation Import