CVE-2026-82918
Received Received - Intake

XXE Vulnerability in Keyence XG VisionTerminal

Vulnerability report for CVE-2026-82918, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: JPCERT/CC

Description

XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 4 associated CPEs
Vendor Product Version / Range
keyence visionterminal *
keyence xg-x_visionterminal *
keyence visionterminal to 5.5.0010 (exc)
keyence xg-x_visionterminal to 3.6.0000 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper handling of XML external entity references in XG VisionTerminal and XG-X VisionTerminal software by Keyence Corporation. When a user opens a specially crafted setting file, the system may disclose sensitive information stored on the device where the software is installed.

Detection Guidance

To detect this vulnerability, check if your system is running affected versions of XG VisionTerminal (Ver.5.5.0010 or earlier) or XG-X VisionTerminal (Ver.3.6.0000 or earlier). Inspect XML parsing behavior in these applications for improper external entity references. Monitor for unusual file access or sensitive data exposure when opening setting files.

Impact Analysis

If exploited, this vulnerability could allow an attacker to access sensitive system information by tricking a user into opening a malicious setting file. This may lead to unauthorized disclosure of confidential data stored on the affected system.

Mitigation Strategies

Immediately update to XG-X VisionTerminal Ver.3.7.0000 or later. If using XG VisionTerminal, upgrade to alternative software as it is end-of-life. Avoid opening untrusted setting files until patched. Verify XML parsing configurations to block external entity references.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82918. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart