CVE-2026-36765: XEE
Published Apr 30, 2026
·Updated
An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.
Affected Software
1 affected component
SpringBlade SpringBlade=4.8.0
Event History
Apr 30, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-36765?
CVE-2026-36765 has a severity rating of high with a CVSS score of 8.8.
2
What type of vulnerability is described in CVE-2026-36765?
CVE-2026-36765 describes an XML external entity (XXE) vulnerability.
3
How can CVE-2026-36765 be exploited?
CVE-2026-36765 can be exploited by authenticated attackers who inject a crafted payload to execute arbitrary code.
4
Which component is affected by CVE-2026-36765?
CVE-2026-36765 affects the /designer/loadReport endpoint of SpringBlade v4.8.0.
5
What is the recommended action to mitigate CVE-2026-36765?
To mitigate CVE-2026-36765, users should upgrade to the latest version of SpringBlade that addresses this vulnerability.