CVE-2026-4374: Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (multiple infrastructure services) allows Serialized Data External Linking, Data Serialization External Entities Blowup.
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Cloud Discovery Service, Recording Service, Routing Service, Queueing Service, Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup.<p>This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.1.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0., from 5.3.0 before 5.3..</p>
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
RTI Connext Professionalto a version that resolves this vulnerability.Fixed in 7.7.0 - Upgrade
Upgrade
RTI Connext Professionalto a version that resolves this vulnerability.Fixed in 7.3.1.1 - Upgrade
Upgrade
RTI Connext Professionalto a version that resolves this vulnerability.Fixed in 6.1.2.34 - Upgrade
Upgrade
RTI Connext Professionalto a version that resolves this vulnerability.Fixed in 6.0.* - Upgrade
Upgrade
RTI Connext Professionalto a version that resolves this vulnerability.Fixed in 5.3.*
Event History
Frequently Asked Questions
What is the severity of CVE-2026-4374?
CVE-2026-4374 has been classified with a high severity level due to its potential for unauthorized access and data exposure.
How do I fix CVE-2026-4374?
To fix CVE-2026-4374, update the affected RTI Connext Professional components to the latest version provided by RTI that addresses this vulnerability.
What are the affected products in CVE-2026-4374?
The affected products include RTI Connext Professional Routing Service, Observability Collector, Recording Service, Queueing Service, and Cloud Discovery Service.
What type of vulnerability is CVE-2026-4374?
CVE-2026-4374 is an improper restriction of XML external entity reference vulnerability, allowing for serialized data external linking.
Who is the vendor for CVE-2026-4374?
The vendor for CVE-2026-4374 is RTI, which develops the affected Connext Professional software.