{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/tis-v5.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.7,"id":"CVE-2026-69101"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["TIS (v5.0.0)"],"_cs_severities":["high"],"_cs_tags":["web-vulnerability","xxe","ssrf","data-exfiltration"],"_cs_type":"advisory","_cs_vendors":["Datavane"],"content_html":"\u003cp\u003eDatavane TIS version 5.0.0 contains an XML external entity (XXE) injection vulnerability arising from an insecurely configured DocumentBuilderFactory within the application's workflow editing functionality. Authenticated attackers can exploit this flaw by submitting a crafted XML payload containing external DTD references to the doEditWorkflow endpoint. Because the application processes these XML inputs with external entities and DTD loading enabled, it is susceptible to both server-side request forgery (SSRF) and out-of-band data exfiltration. Successful exploitation allows an attacker to force the server to initiate arbitrary outbound HTTP requests to attacker-controlled infrastructure and retrieve the contents of local system files. This exposes sensitive information readable by the TIS service user, including internal configuration files and Derby database credentials, which may be leveraged for further network penetration or lateral movement within the environment.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the Datavane TIS application using valid user credentials.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious XML payload designed to trigger an external entity expansion, including a reference to a local system file (e.g., /etc/passwd or database configuration files).\u003c/li\u003e\n\u003cli\u003eAttacker directs the payload to the doEditWorkflow endpoint within the application interface.\u003c/li\u003e\n\u003cli\u003eThe application receives the XML document as part of the taskScript parameter in an HTTP POST request.\u003c/li\u003e\n\u003cli\u003eThe server-side XML parser (DocumentBuilderFactory) processes the DTD, resolving the external entity to the attacker-defined URI.\u003c/li\u003e\n\u003cli\u003eThe application performs an outbound network request to the specified URI, facilitating SSRF or exfiltrating the contents of the referenced local file via the request body or response.\u003c/li\u003e\n\u003cli\u003eAttacker captures the exfiltrated data on their controlled listener, obtaining target configuration and database credentials.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-69101 leads to full information disclosure of sensitive configuration data and database credentials stored on the application server. This impact is significant for organizations deploying Datavane TIS, as it grants attackers the ability to compromise the backend database and potentially gain further access to the internal network infrastructure. No specific number of victims has been confirmed, but the vulnerability affects all instances of Datavane TIS v5.0.0.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate Datavane TIS to the latest patched version immediately upon release to remediate the insecure DocumentBuilderFactory configuration.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the application server to block unauthorized outbound network connections, effectively limiting the impact of potential SSRF and OOB exfiltration attempts.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for HTTP POST requests to the 'doEditWorkflow' endpoint containing XML structures with 'DOCTYPE' or 'ENTITY' declarations.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T16:12:17Z","date_published":"2026-08-14T16:12:17Z","id":"https://feed.craftedsignal.io/briefs/2026-08-datavane-tis-xxe/","summary":"Datavane TIS v5.0.0 is vulnerable to XML external entity injection in the doEditWorkflow endpoint, allowing authenticated attackers to perform SSRF and exfiltrate sensitive local files.","title":"Datavane TIS XXE Vulnerability CVE-2026-69101","url":"https://feed.craftedsignal.io/briefs/2026-08-datavane-tis-xxe/"}],"language":"en","title":"CraftedSignal Threat Feed - TIS (V5.0.0)","version":"https://jsonfeed.org/version/1.1"}