CVE-2026-3511Disclosure

LOWCVSS 8.6 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends request containing a specially crafted XML document to /sign endpoint of the local HTTP server run by the application.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-19); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-19: 3Mentions · 2026-03-23: 1Technical Details · 2026-03-19: 3Technical Details · 2026-03-23: 103-1903-23
Signal classification1 categories
Disclosure
4100.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-03-193
Disclosure3
2026-03-231
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-3511 Improper Restriction of XML External Entity Reference vulnerability in http://XMLUtils.java in http://Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSR… https://www.cve.org/CVERecord?id=CVE-2026-3511

    Post summary

    The text reports CVE-2026-3511 as an improper restriction of XML External Entity Reference in XMLUtils.java, indicating a potential for remote unauthenticated attackers to conduct SSRF-like attacks.

    00000108
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-3511 - High Improper Restriction of XML External Entity Reference vulnerability in http://XMLUtils.java in http://Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request F... https://www.thehackerwire.com/vulnerability/CVE-2026-3511/ https://t.co/x1zzpPnGWv

    Post summary

    The text is a typical vulnerability advisory, describing the CVE’s technical details and severity without indicating proof of exploit, active attacks, or available fixes.

    0000040
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3511 XXE Vulnerability in http://Slovensko.Digital Autogram Enables Unauthenticated SSRF Attack https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3511

    Post summary

    The brief note announces CVE‑2026‑3511 as an XXE flaw permitting unauthenticated SSRF, but offers no proof of exploitation, patch, or evidence of active attacks.

    0000047
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-3511: HIGH] Vulnerability in http://Slovensko.Digital Autogram allows SSRF attack, enabling access to local files. Exploitation via crafted website request to the /sign endpoint.#cve,CVE-2026-3511,#cybersecurity https://cvefind.com/CVE-2026-3511

    Post summary

    The post announces a high‑severity SSRF vulnerability in Slovensko.Digital Autogram that can be exploited via crafted requests to the /sign endpoint, granting access to local files, but offers no patch or exploit details.

    0000044
    603 followersView on X

Explore more