ZeroHour

CVE-2026-71375

Unauthenticated XXE in Hitachi Cosminexus Component Container

CVSS 3.1
7.4 high
EPSS
<1%p16
Published
()
Modified
AI analysis

CVE-2026-71375 is an XML External Entity (XXE) injection flaw (CWE-611) in the Component Container of Hitachi's Cosminexus application server platform, affecting a wide span of maintenance levels from the 09-00 series through the 11-70 series. An unauthenticated remote attacker can trigger it by inducing the container's XML processing to resolve external entity references in a crafted XML document, for example through an application that feeds untrusted XML to the container; the high attack complexity (AC:H) in the CVSS vector indicates that exploitation depends on such a reachable parsing path rather than succeeding on every request. A successful attack yields high-impact information disclosure (reading local files or internal resources accessible to the server) and can also produce a denial of service, while integrity is unaffected (C:H/I:N/A:H). Organizations running affected Cosminexus Component Container versions — predominantly enterprise and government estates built on this application server — are potentially exposed, since no authentication or user interaction is required. There is no evidence of exploitation in the wild: it is not in CISA KEV, EPSS estimates only a ~0.2% probability of exploitation within 30 days (16th percentile), and no public proof-of-concept is known.

What to do: Upgrade each affected Cosminexus Component Container stream to its fixed maintenance level — explicitly listed fixes include 11-70-03, 11-60-03, 11-20-10, 11-00-13, 09-87-10, 09-80-05 and 09-70-28, with the vendor's successor maintenance versions required for the 11-50/11-40/11-30/11-10/09-50/09-00 streams. Until patched, disable or restrict external entity/DTD resolution in the XML parsing used by the component container and limit the server's ability to fetch external resources. Check whether any of your applications pass attacker-supplied XML documents through this container's XML processing, as that determines practical reachability.

Affected
Hitachi Cosminexus Component Container11-70-01 before 11-70-03; 11-60 before 11-60-03; 11-50 through 11-50-03; 11-40 through 11-40-03; 11-30 through 11-30-08; 11-20 before 11-20-10; 11-10 through 11
Estimated exposure
unknown; plausibly thousands to tens of thousands of enterprise installations (concentrated in Japan), with only a limited subset internet-exposed — No public install-base counts or internet-exposure scan data are available for Cosminexus Component Container; it is an enterprise application server typically deployed on internal networks within Japanese enterprises and government…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.

Weakness
CWE-611
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H

In the news

No ingested article mentions this CVE yet.