CVE-2026-71375

7.4

Hitachi · Cosminexus Component Container

Hitachi Cosminexus Component Container contains an XML external entity (XXE) vulnerability, allowing unauthenticated attackers to potentially access sensitive information.

Executive summary

A critical XML external entity vulnerability in the Hitachi Cosminexus Component Container allows unauthenticated attackers to perform information disclosure or cause a denial of service.

Vulnerability

This is an XML external entity (XXE) injection flaw (CWE-611) that occurs due to improper processing of XML data. An unauthenticated attacker can exploit this remotely over a network to read arbitrary files or disrupt service availability.

Business impact

Successful exploitation of this vulnerability could lead to the unauthorized disclosure of sensitive server-side files, such as configuration data or credentials, posing a significant risk to data confidentiality. With a CVSS score of 7.4, this high-severity flaw also allows for potential denial of service, which could disrupt critical business operations reliant on the application.

Remediation

Immediate Action: Update the Hitachi Cosminexus Component Container to the patched versions specified in the vendor security advisory (e.g., 11-70-03, 11-60-03, 11-20-10, or 11-00-13).

Proactive Monitoring: Review application access logs for unusual XML payloads or attempts to access system files through web requests.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block XML entities or malformed XML input to provide temporary protection until patching is completed.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS severity and the potential for unauthorized file access, administrators must prioritize the application of vendor-supplied patches. Please refer to the official Hitachi security notification to verify the specific patch requirements for your current version, and perform testing in a staging environment before deploying to production systems.

More Hitachi CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources