Junglewise Threat Intelligence

CVE-2026-38429: Alkacon OpenCMS XXE in Admin Import DB feature

CVE-2026-38429 · Severity: critical · CVSS 9.8 · Published 2026-05-05

Technologies: Alkacon Software OpenCms.

Executive brief

OpenCMS, a popular open-source content management system, contains a critical security flaw in its database import tool. An attacker can exploit this by uploading a specially crafted ZIP file, allowing them to potentially steal sensitive files from the server or disrupt operations. This could lead to a full compromise of the website's data and underlying infrastructure.

Technical details

OpenCMS v20 and prior versions are vulnerable to an XML External Entity (XXE) injection (CWE-611) within the Admin Import DB functionality. The vulnerability exists because the application's XML parser does not securely handle external entity references when processing the 'manifest.xml' file contained within a user-uploaded .zip archive. A remote, unauthenticated attacker can exploit this by submitting a malicious ZIP file to the import interface. Successful exploitation can lead to arbitrary file disclosure (OOB-XXE), server-side request forgery (SSRF), or denial-of-service. A patch has been identified in the alkacon/opencms-core repository (commit e3e41e5).

Affected products

  • Alkacon Software OpenCMS v20 and earlier

Timeline

  • 2026-05-05: disclosed
  • 2026-05-05: advisory: NVD publication date

References