Junglewise Threat Intelligence

CVE-2026-79572: Distribution Management XXE in level-rule module

CVE-2026-79572 · Severity: high · CVSS 7.5 · Published 2026-09-08

Vendors: Unknown.

Executive brief

Distribution Management is a system for managing software distribution workflows. The level-rule module, used for parsing XML-based configuration rules, fails to restrict external entity processing, allowing attackers to read sensitive files from the server, scan internal networks, or execute server-side attacks without authentication.

Technical details

An XXE (XML External Entity) vulnerability exists in the XmlParseService.doXMLParse() method in the level-rule module's /test endpoint. The org.dom4j.io.SAXReader is instantiated without any security features to disable DTD processing or external entities. An unauthenticated attacker can POST a crafted XML payload containing external entity declarations to exfiltrate files via out-of-band (OOB) techniques, scan internal networks, or launch SSRF attacks. The vulnerability is network-accessible, requires no authentication, and can be exploited by any remote attacker who can reach the /test endpoint.

Affected products

  • <UNKNOWN> Distribution Management v1.0.0

Timeline

  • 2026-09-08: disclosed

References