CVE-2026-61586: 
Java vulnerability analysis and mitigation

Overview

CVE-2026-61586 is an improper XInclude resource restriction vulnerability in Copernik XML Factory (Maven artifact eu.copernik:copernik-xml-factory) affecting all versions through 0.1.1. When running on the stock JDK provider (i.e., Apache Xerces is absent from the classpath), the library fails to block xi:include resolution even after an application enables XInclude via setXIncludeAware(true), breaking the library's documented security guarantee. The vulnerability was discovered by Ta Duc Thien and Duc Anh Nguyen (Danzation), first published on June 26, 2026, and added to the GitHub Advisory Database on October 2, 2026. It carries a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Security Advisory).

Technical details

The root cause is classified as CWE-611 (Improper Restriction of XML External Entity Reference). The stock JDK's XInclude processor resolves xi:include hrefs by consulting the parser's EntityResolver rather than honoring the ACCESS_EXTERNAL_DTD and ACCESS_EXTERNAL_SCHEMA attributes — a behavior the library's hardening logic incorrectly relied upon. As a result, setting those attributes to empty strings (the library's prior mitigation) had no effect on XInclude resolution. Exploitation requires four concurrent conditions: (1) the application uses XmlFactories.newDocumentBuilderFactory(), XmlFactories.newSAXParserFactory(), or XmlFactories.harden() on an XMLReader; (2) Apache Xerces is not on the classpath; (3) XInclude is explicitly enabled via setXIncludeAware(true) or an equivalent reader feature; and (4) the application parses XML from an untrusted source. The fix (commits 2fa042c and e5febc6) installs a deny-all FallbackDenyResolver as a non-overridable floor on every DocumentBuilder and XMLReader produced, blocking all external resource fetches including xi:include hrefs (GitHub Commit 2fa042c, GitHub Commit e5febc6).

Impact

Successful exploitation allows an unauthenticated remote attacker to read arbitrary local files on the server hosting the vulnerable application (information disclosure) by crafting xi:include elements with file:// hrefs, or to perform Server-Side Request Forgery (SSRF) by using http:// hrefs to probe and interact with internal network endpoints not directly accessible to the attacker. There is no integrity or availability impact — the vulnerability is confined to confidentiality. Sensitive files such as configuration files, credentials, or private keys readable by the JVM process could be exfiltrated, and SSRF could facilitate reconnaissance of internal infrastructure (GitHub Advisory, Security Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. The attack requires specific deployment conditions (stock JDK provider, XInclude enabled, untrusted XML input), which limits the exposed population, though no authentication is required from the attacker once those conditions are met.

Exploitation steps

  1. Reconnaissance: Identify applications using eu.copernik:copernik-xml-factory version ≤ 0.1.1 that accept XML input from untrusted sources (e.g., API endpoints, file upload features). Confirm that Apache Xerces (xercesImpl) is absent from the application's classpath and that XInclude is enabled.
  2. Craft malicious XML payload: Construct an XML document containing an xi:include element targeting a sensitive local file or internal HTTP endpoint. For local file disclosure:
<?xml version="1.0"?>
<root xmlns:xi="http://www.w3.org/2001/XInclude">
  <xi:include href="file:///etc/passwd" parse="text"/>
</root>

For SSRF:

<?xml version="1.0"?>
<root xmlns:xi="http://www.w3.org/2001/XInclude">
  <xi:include href="http://169.254.169.254/latest/meta-data/" parse="text"/>
</root>
  1. Submit payload: Deliver the crafted XML to the vulnerable application endpoint that parses untrusted XML (e.g., via HTTP POST, file upload, or any XML-consuming API).
  2. Retrieve exfiltrated data: The application's XML parser resolves the xi:include reference and embeds the file contents or HTTP response body into the parsed document. If the application reflects parsed XML content in its response, the attacker reads the exfiltrated data directly; otherwise, out-of-band techniques (e.g., DNS or HTTP callbacks to an attacker-controlled server) may be used via the SSRF vector (GitHub Advisory, Security Advisory).

Indicators of compromise

  • Network: Unexpected outbound HTTP requests from the application server to internal IP ranges (e.g., RFC 1918 addresses, cloud metadata endpoints such as 169.254.169.254) originating from the JVM process; DNS lookups for internal hostnames triggered by the XML parser.
  • Logs: Application or web server access logs showing XML submission to parsing endpoints followed by anomalous response content containing file data; Java exception logs referencing xi:include resolution failures (if partially blocked) or unexpected EntityResolver activity.
  • File System: No direct file system artifacts are created by this vulnerability, but audit logs may show the JVM process reading sensitive files (e.g., /etc/passwd, application configuration files) outside normal operation patterns.
  • Process: Unusual network connections initiated by the Java process to internal endpoints not part of normal application behavior, detectable via network monitoring tools or EDR solutions.

Mitigation and workarounds

Upgrade eu.copernik:copernik-xml-factory to version 0.1.2, which fixes the defect by installing a deny-all FallbackDenyResolver as a non-overridable floor on all DocumentBuilder and XMLReader instances produced by the stock JDK provider (v0.1.2 Release). As an immediate workaround, add Apache Xerces (xercesImpl) to the application's classpath — the library will then select the Xerces provider, which is not affected by this vulnerability. Alternatively, avoid calling setXIncludeAware(true) on factories obtained from this library when the stock JDK provider is in use, or ensure that untrusted XML is not parsed in this configuration (Security Advisory).

Additional resources


Source: This report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-61741CRITICAL9.3
  • Java logoJava
  • org.http4s:http4s-scala-xml_2.12
NoYesSep 24, 2026
CVE-2026-54049HIGH8.7
  • Java logoJava
  • org.sakaiproject.conversations:sakai-conversations-impl
NoNoOct 01, 2026
CVE-2026-61586HIGH8.2
  • Java logoJava
  • eu.copernik:copernik-xml-factory
NoYesOct 02, 2026
CVE-2026-77422HIGH7.5
  • Java logoJava
  • opensearch-fips-3
NoYesSep 23, 2026
CVE-2026-57168NONEN/A
  • Java logoJava
  • io.openremote:openremote-manager
NoYesSep 23, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management