← Back

CVE-2026-4374

nvd nist
Published: Apr 1, 2026Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: 3f572a00-62e2-4423-959a-7ea25eff1638 (Secondary)

Description

Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup.<p>This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.1.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.</p>

Affected (5)

1 product
Connext Professional
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Rti
From 5.3.0 to 5.3.1.45
From 6.0.0 to 6.0.1.40
From 6.1.0 to 6.1.2.27
From 7.0.0 to 7.3.1.1
From 7.4.0 to 7.7.0

References (1)

Source: 3f572a00-62e2-4423-959a-7ea25eff1638
Vendor Advisory

Timeline

No history available yet.