Executive brief
Alkacon OpenCms is an open-source content management system used by various enterprises to manage web content. A security vulnerability in how the system handles XML data allows an attacker to perform an XML External Entity (XXE) attack. This could allow an unauthenticated remote attacker to read sensitive files from the server or probe internal network resources, potentially leading to a breach of confidential information.
Technical details
Alkacon OpenCms is vulnerable to an XML External Entity (XXE) injection vulnerability in its CMIS (Content Management Interoperability Services) implementation. The vulnerability exists within the 'CmisAtomPubServlet' (mapped to /cmisatom/*), which utilizes the Apache Chemistry library. Specifically, the /query endpoint fails to properly restrict external entity references in incoming XML POST requests. An unauthenticated attacker can exploit this by submitting a crafted XML document containing a DOCTYPE declaration pointing to an external or local DTD file. This can be used to perform out-of-band data exfiltration or local file disclosure (LFD) by leveraging existing DTDs on the filesystem (e.g., nmap.dtd). The issue is resolved in OpenCms version 16.0.
Affected products
- Alkacon opencms-core < 16.0
Timeline
- 2023-11-21: disclosed: Initial research blog post by watchTowr Labs published
- 2026-05-08: advisory: GitHub Advisory and CVE published
- 2026-05-08: patched: OpenCms 16.0 released with fixes