Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Product Security

XXE injection in Process Eval

Avatar Pragati Kharel
July 27, 2026 08:18
Follow
Advisory ID GVD-2026-002
CVSSv 4.0 Vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CVSSv 4.0 Base Score 8.9
Severity
High
CVE
Pending
Date Published 2026-07-27
Description
An authenticated attacker with search access can craft a malicious XML payload with external entity references to read arbitrary files on the server (e.g., /etc/passwd ) or perform Server-Side Request Forgery (SSRF) attacks against internal services.
Affected Product
Eval v5.3.0 and earlier. 
Solution
Upgrade to Eval v5.4.0.

Comments

Article is closed for comments.

Related articles

  • Evaluation Process Plugin
Was this article helpful? 0 out of 0 found this helpful
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.