CVE-2026-3511 PUBLISHED

Assigner: SK-CERT
Reserved: 04.03.2026 Published: 19.03.2026 Updated: 19.03.2026

Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends request containing a specially crafted XML document to /sign endpoint of the local HTTP server run by the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
CVSS Score: 8.6

Product Status

Vendor Slovensko.Digital
Product Autogram
Versions Default: unaffected
  • affected from 0 to 2.7.2 (excl.)

Credits

  • Martin Orem from Binary House finder

References

Problem Types

  • CWE-611 Improper Restriction of XML External Entity Reference CWE

Impacts

  • CAPEC-664 Server Side Request Forgery
  • CAPEC-126 Path Traversal