Executive brief
RTI Connext Professional, a suite of tools used for real-time data distribution in industrial and mission-critical systems, contains a vulnerability in how it processes XML data. An attacker could exploit this to access sensitive files or cause a system shutdown by sending specially crafted data. This could lead to unauthorized data exposure or a disruption of critical communications and operations.
Technical details
An Improper Restriction of XML External Entity Reference (XXE) vulnerability (CWE-611) exists in several RTI Connext Professional components, including the Routing, Recording, and Cloud Discovery services. The flaw occurs during the processing of serialized data, where the XML parser fails to restrict external entity references. A remote, unauthenticated attacker can exploit this by sending malicious XML payloads to trigger 'Serialized Data External Linking' or 'Data Serialization External Entities Blowup.' This can result in the disclosure of sensitive information from the host filesystem or a denial-of-service (DoS) condition. Patches are available in versions 7.7.0, 7.3.1.1, and 6.1.2.34.
Affected products
- RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) 7.4.0 before 7.7.0, 7.1.0 before 7.3.1.1, 6.1.0 before 6.1.2.34, 6.0.0 before 6.0.*, 5.3.0 before 5.3.*
Timeline
- 2026-04-01: disclosed: Initial publication date
- 2026-06-17: advisory: Last updated by vendor