CVE-2026-6501
XML External Entity Processing in jOpenDocument
Publication date: 2026-05-04
Last updated on: 2026-05-04
Assigner: TCS-CERT
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ilm_informatique | jopendocument | 1.5 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-611 | The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an improper restriction of XML external entity (XXE) references in the ILM Informatique jOpenDocument software, specifically version 1.5. It allows an attacker to exploit the way the software processes XML data, potentially causing a Data Serialization External Entities Blowup.
How can this vulnerability impact me? :
The vulnerability can lead to exploitation through XML external entity processing, which may result in denial of service or resource exhaustion due to the external entities blowup. This can affect the availability and reliability of the affected software.