Junglewise Threat Intelligence

CVE-2026-8396: Netcad NetGIS XXE in Serialized Data External Linking

CVE-2026-8396 · Severity: high · CVSS 7.5 · Published 2026-07-17

Executive brief

Netcad NetGIS, a geographic information system platform, contains a security flaw in how it processes data. An attacker can exploit this to remotely access sensitive files or internal network resources that should be protected. This could lead to the exposure of confidential organizational data or mapping information.

Technical details

An Improper Restriction of XML External Entity Reference (XXE) vulnerability (CWE-611) exists in Netcad NetGIS versions 5.0.66 through 7.2.2. The vulnerability is rooted in the application's handling of serialized data and XML input, which fails to properly restrict external entity references. A remote, unauthenticated attacker can exploit this over the network by sending a specially crafted XML payload. Successful exploitation allows the attacker to read local files, perform server-side request forgery (SSRF), or cause a denial-of-service condition. The issue is addressed in version 7.2.2.

Affected products

  • Netcad Software Inc. NetGIS 5.0.66 to 7.2.2

Timeline

  • 2026-07-17: advisory: Published by TR-CERT and NVD

References