CVE-2026-91197

Source
https://cve.org/CVERecord?id=CVE-2026-91197
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91197.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-91197
Published
2026-09-14T22:10:55Z
Modified
2026-09-18T03:30:17Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Flowable flowable-engine through 8.0.0 XXE via ProcessDiagramLayoutFactory
Details

Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resources. Attackers with process deployment privileges can embed DOCTYPE declarations with external entities in BPMN files to read arbitrary local files or trigger requests to internal network endpoints when diagram layout is computed.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-611"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/91xxx/CVE-2026-91197.json"
}
References

Affected packages

Git / github.com/flowable/flowable-engine

Affected ranges

Type
GIT
Repo
https://github.com/flowable/flowable-engine
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "8.0.0"
        },
        {
            "fixed": "8.0.0"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

flowable-6.*
flowable-6.0.0
flowable-6.0.0.RC1
flowable-6.1.0
flowable-6.1.2
flowable-6.2.0
flowable-6.2.1
flowable-6.3.0
flowable-6.3.1
flowable-6.4.0
flowable-6.4.1
flowable-6.4.2
flowable-6.6.0
flowable-6.7.0
flowable-6.7.1
flowable-6.7.2
flowable-6.8.0
flowable-7.*
flowable-7.0.0
flowable-7.0.0.M1
flowable-7.0.0.M2
flowable-7.0.1
flowable-7.1.0
flowable-7.2.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-91197.json"