Junglewise Threat Intelligence

CVE-2026-71375: Hitachi Cosminexus Component Container XXE vulnerability

CVE-2026-71375 · Severity: high · CVSS 7.4 · Published 2026-09-08

Technologies: Hitachi Cosminexus Component Container. Vendors: Hitachi.

Executive brief

Cosminexus Component Container is middleware used to deploy service-oriented business applications. The software contains an XML External Entity (XXE) vulnerability in its SOAP communication layer that allows attackers to read sensitive files or cause service outages. This affects critical infrastructure supporting business operations across Windows, Linux, and AIX platforms.

Technical details

Cosminexus Component Container contains an XXE (XML External Entity) vulnerability in the SOAP communication infrastructure, specifically in user-defined reception services (SOAP reception services) and SOAP adapters operating in SOAP 1.1 mode. The vulnerability is exposed via network-accessible SOAP endpoints and requires no authentication or user interaction. An unauthenticated attacker can craft malicious XML payloads to extract sensitive files from the server or trigger denial-of-service conditions. Fixes are available across supported versions: Cosminexus V11 versions 11-70-03, 11-60-03, 11-20-10, 11-00-13 and Cosminexus V9 versions 09-87-10, 09-80-05, 09-70-28.

Affected products

  • Hitachi uCosminexus Service Architect V9 09-00 to 09-70; V11 11-00 to 11-70
  • Hitachi uCosminexus Service Platform V9 09-00 to 09-87; V11 11-00 to 11-70
  • Hitachi Cosminexus Component Container V9 09-00 to 09-87; V11 11-00 to 11-70

Timeline

  • 2026-09-08: disclosed: Vulnerability published by Hitachi

References

Related threats