CVE-2026-3511

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends request containing a specially crafted XML document to /sign endpoint of the local HTTP server run by the application.
Configurations

No configuration.

History

19 Mar 2026, 12:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-19 12:16

Updated : 2026-03-19 13:25


NVD link : CVE-2026-3511

Mitre link : CVE-2026-3511

CVE.ORG link : CVE-2026-3511


JSON object : View

Products Affected

No product.

CWE
CWE-611

Improper Restriction of XML External Entity Reference