peter bassill · operator
$ cve CVE-2021-23926 JSON

CVE-2021-23926

9.1
CRITICAL · CVSS 3.1 · EPSS 6.2% (pctl 93)

In your normal cycle

Critical by CVSS (9.1), but no sign of active exploitation.

Description

The XML parsers used by XMLBeans up to version 2.6.0 did not set the properties needed to protect the user from malicious XML input. Vulnerabilities include possibilities for XML Entity Expansion attacks. Affects XMLBeans up to and including v2.6.0.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
EPSS6.22% — more likely to be exploited than 93% of all CVEs
WeaknessCWE-776
On CISA KEVno
Public exploitnone known
Published2021-01-14
Last modified2026-06-17

Affected (7)

VendorProduct
apachexmlbeans
debiandebian linux
netapponcommand unified manager core package
netappsnap creator framework
netappsnapmanager
oraclemiddleware common libraries and tools
oraclepeoplesoft enterprise peopletools

References

→ the Explorer  ·  watch your stack  ·  NVD