Junglewise Threat Intelligence

CVE-2026-82918: Keyence XG VisionTerminal XML external entity injection

CVE-2026-82918 · Severity: medium · CVSS 5.5 · Published 2026-09-03

Executive brief

Keyence's XG VisionTerminal and XG-X VisionTerminal are industrial automation software tools used to design and manage vision systems. A flaw in how they process XML configuration files allows attackers to extract sensitive information from the system by tricking users into opening a malicious settings file. This could expose system credentials, configuration data, or other confidential information stored on affected machines.

Technical details

The vulnerability is an XML external entity (XXE) injection flaw (CWE-611) that arises from improper restriction of XML external entity references. The affected components fail to properly disable or validate external entity processing when parsing XML-based setting files. An attacker can craft a malicious setting file containing XXE payloads to read arbitrary files from the system where the software is installed. Successful exploitation requires user interaction—a user must open the specially crafted setting file. The primary impact is confidentiality violation; the attacker can disclose sensitive information stored locally. Patches are available: XG-X VisionTerminal should be updated to version 3.7.0000 or later, while XG VisionTerminal is end-of-life and users are advised to migrate to XG-X VisionTerminal.

Affected products

  • Keyence XG-X VisionTerminal 3.6.0000 and earlier
  • Keyence XG VisionTerminal 5.5.0010 and earlier

Timeline

  • 2026-09-02: disclosed
  • 2026-09-03: advisory

References