CVE 5.5 MEDIUM

NSA GRASSMARLIN Improper Restriction of XML External Entity Reference_CVE-2026-6807

5.5 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Description

A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to
trigger improper handling of XML input, which may result in unintended
exposure of sensitive information. The flaw stems from insufficient
hardening of the XML parsing process.

Basic Information

ID CVE-2026-6807
Source icscert
Published Apr 28, 2026 at 17:41

Affected Product

Vendor NSA
Product GRASSMARLIN
Version All versions
Affected Versions NSA GRASSMARLIN All versions

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.