What is CVE-2026-69101?
Datavane TIS v5.0.0 is affected by an XXE injection vulnerability via the doEditWorkflow endpoint, allowing authenticated attackers to perform SSRF and exfiltrate data through crafted XML payloads. Updating to the latest version is recommended to mitigate the risk.
Azərbaycanca: Datavane TIS v5.0.0 proqramında autentifikasiya olunmuş istifadəçilərə "doEditWorkflow" endpoint-i vasitəsilə xüsusi hazırlanmış XML yükü göndərərək server tərəfli sorğu saxtakarlığı (SSRF) və məlumat sızdırma imkanı verən XXE injection zəifliyi aşkarlanıb. Təsirə məruz qalmamaq üçün proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-611
FAQ2
Which version of Datavane TIS is affected by CVE-2026-69101?
The CVE-2026-69101 vulnerability affects Datavane TIS version v5.0.0.
What measure should be taken to protect against CVE-2026-69101?
It is recommended to update Datavane TIS to the latest version to protect against this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.