Orizon[verified]@OrizonCyberDisclosure
A critical XML external entity injection flaw (CVE-2026-40042) in Pachno 1.0.6 allows unauthenticated attackers to read data; a patch is now available.
0day Signal@0dayPublishingDisclosure
The note announces CVE‑2026‑40042 in Pachno 1.0.6, describing an unauthenticated XML External Entity (XXE) vulnerability that allows trivial file disclosure via the Wiki TextParser.
Infoflowcloud@infoflowcloudDisclosure
Announces CVE-2026‑40042, an XML external entity injection flaw allowing unauthenticated file reading in Pachno 1.0.6.
CVE@CVEnewDisclosure
CVE‑2026‑40042 exposes an XML external entity injection flaw in Pachno 1.0.6 that lets unauthenticated users read any file through unsafe XML parsing.
CVEFind.com@CveFindComDisclosure
CVE‑2026‑40042 is a critical XML External Entity injection flaw in Pachno 1.0.6 that lets attackers read files via the TextParser helper in wiki content, with no patches or proofs of concept referenced.