CVE-2026-38429Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-611

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 6 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked at 4 mentions on most recent observed day (2026-05-12)
  • 6 total mentions across 2 days

Deep dive

Activity timeline6 mentions / 2d
01234Mentions · 2026-05-05: 2Mentions · 2026-05-12: 4Technical Details · 2026-05-05: 2Technical Details · 2026-05-12: 305-0505-12
Signal classification2 categories
Disclosure
583.3%
General
116.7%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-052
Disclosure2
2026-05-124
Disclosure3General1
Full discourse6 posts
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE: CVE-2026-38429 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user…

    Post summary

    The advisory announces a critical XML External Entity (XXE) vulnerability in OpenCMS before v20, providing CVSS scores and severity, but does not include a PoC, exploit, patch, or evidence of active exploitation.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-38429 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text announces CVE-2026-38429 with a critical severity rating and detailed CVSS score.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-38429 (CVSS 9.8) — multiple products. CVE: CVE-2026-38429 CVSS: 9.8 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces CVE-2026-38429, a critical vulnerability with a CVSS score of 9.8, but it does not provide any PoC, exploit, or patch information.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-38429-advisory #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text merely links to a research page about CVE-2026-38429 without providing explicit details on exploitation, patches, or technical aspects.

    0000024
    210 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-38429 OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a … https://www.cve.org/CVERecord?id=CVE-2026-38429 ----- Traducción: CVE-2026-38429 Ope… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-38429 as an XXE vulnerability in OpenCMS versions 20 and earlier, detailing the affected feature and the insecure XML parsing issue, but no PoC, exploit code, activity, or patch is provided.

    0000043
    75 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-38429 OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a … https://www.cve.org/CVERecord?id=CVE-2026-38429

    Post summary

    The text announces CVE-2026-38429 as an XXE flaw in OpenCMS v20 and earlier, detailing insecure XML parsing in the Admin Import DB feature and linking to the official CVE record.

    00000159
    57.4K followersView on X

Explore more