CVE-2026-34401 Details
Description
XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related to malicious DTD files where an attacker to craft a malicious XML file that loads a DTD that causes XML Notepad to make outbound HTTP/SMB requests, potentially leaking local file contents or capturing the victim's NTLM credentials. This issue has been patched in version 2.9.0.21.
A vulnerability in XML Notepad prior to version 2.9.0.21 allows for XML External Entity (XXE) injection by not disabling Document Type Definition (DTD) processing by default. This oversight enables attackers to craft malicious XML files that, when opened in XML Notepad, cause the application to make unintended outbound HTTP or SMB requests. Such actions could lead to the leakage of local file contents or the capture of NTLM credentials. The vulnerability arises from the automatic resolution of external entities in DTDs, creating a risk of unauthorized data access or transmission.
Users are advised to update to XML Notepad version 2.9.0.21, where this vulnerability has been addressed. In the updated version, the default setting for DTD processing has been changed to 'Ignore DTD=True', and users are prompted to review the documentation regarding the risks of enabling DTD processing for untrusted sources.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| microsoft xml notepad | < 2.9.0.21 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 13, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | CVE Modified | CISA-ADP |
| Mar 31, 2026 | New CVE Received | [email protected] |