CVE-2026-40042Disclosure

LOWCVSS 9.3 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in the TextParser helper. Attackers can inject malicious XML entities through wiki table syntax and inline tags in issue descriptions, comments, and wiki articles to trigger entity resolution via simplexml_load_string() without LIBXML_NONET restrictions.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-403

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 5 signals
  • Disclosure: 5 classified signals
  • Peaked at 4 mentions on most recent observed day (2026-04-14)
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-13: 1Mentions · 2026-04-14: 4Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 404-1304-14
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-131
Disclosure1
2026-04-144
Disclosure4
Full discourse5 posts
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-40042 — CVSS 9.8/10 ██████████ Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/ajIdaKIFog

    Post summary

    A critical XML external entity injection flaw (CVE-2026-40042) in Pachno 1.0.6 allows unauthenticated attackers to read data; a patch is now available.

    1000031
    23 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-40042: Pachno 1.0.6 Wiki TextParser XML... Unauthenticated XXE via wiki markup hits simplexml_load_string() without LIBXML_NONET—trivial file disclosure through i... https://zerodaysignal.com/vulnerability/CVE-2026-40042 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The note announces CVE‑2026‑40042 in Pachno 1.0.6, describing an unauthenticated XML External Entity (XXE) vulnerability that allows trivial file disclosure via the Wiki TextParser.

    0000033
    218 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-40042 Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in… https://www.cve.org/CVERecord?id=CVE-2026-40042 ----- Traducción: CVE-2026-40042 Pac… http://infoflow.cloud`

    Post summary

    Announces CVE-2026‑40042, an XML external entity injection flaw allowing unauthenticated file reading in Pachno 1.0.6.

    0000023
    71 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-40042 Pachno 1.0.6 contains an XML external entity injection vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting unsafe XML parsing in… https://www.cve.org/CVERecord?id=CVE-2026-40042

    Post summary

    CVE‑2026‑40042 exposes an XML external entity injection flaw in Pachno 1.0.6 that lets unauthenticated users read any file through unsafe XML parsing.

    00000161
    57.2K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-40042: CRITICAL] Pachno 1.0.6 vulnerability: XML external entity injection allows attackers to read files. Exploit in TextParser helper through wiki content can trigger unsafe XML parsing.#cve,CVE-2026-40042,#cybersecurity https://cvefind.com/CVE-2026-40042

    Post summary

    CVE‑2026‑40042 is a critical XML External Entity injection flaw in Pachno 1.0.6 that lets attackers read files via the TextParser helper in wiki content, with no patches or proofs of concept referenced.

    0000031
    620 followersView on X

Explore more