CVE-2026-82918: Medium severity Keyence Corporation XG VisionTerminal vulnerability
Published Sep 3, 2026
·Updated
XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.
Affected Software
2 affected components
Keyence Corporation XG VisionTerminal
Keyence Corporation XG-X VisionTerminal
Event History
Sep 3, 2026
CVE Published
via MITRE·12:49 PM
Data Sourced
via MITRE·12:49 PM
DescriptionSeverity
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
An attacker must persuade a user to open a specially crafted setting file in XG VisionTerminal or XG-X VisionTerminal. The vulnerability requires local access and user interaction.
2
What is the likely impact of successful exploitation?
Successful exploitation may disclose sensitive information stored on the system where the affected software is installed. The provided information does not indicate impacts to integrity or availability.