CVE-2026-2252: XML External Entity (XXE) vulnerability resulting in Server-Side Request Forgery (SSRF)
An XML External Entity (XXE) vulnerability allows malicious user to perform Server-Side Request Forgery (SSRF) via crafted XML input containing malicious external entity references. This issue affects Xerox FreeFlow Core versions up to and including 8.0.7. Please consider upgrading to FreeFlow Core version 8.1.0 via the software available on - https://www.support.xerox.com/en-us/product/core/downloads
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2252?
CVE-2026-2252 has a high severity rating due to its potential for Server-Side Request Forgery (SSRF) attacks.
How do I fix CVE-2026-2252?
To fix CVE-2026-2252, update Xerox FreeFlow Core to version 8.0.8 or later to mitigate the vulnerability.
What software is affected by CVE-2026-2252?
CVE-2026-2252 affects Xerox FreeFlow Core versions up to and including 8.0.7.
What type of vulnerability is CVE-2026-2252?
CVE-2026-2252 is an XML External Entity (XXE) vulnerability that leads to Server-Side Request Forgery (SSRF).
Can CVE-2026-2252 be exploited remotely?
Yes, CVE-2026-2252 can be exploited remotely by sending crafted XML input containing malicious external entity references.