CVE-2026-4374 Details
Description
Improper Restriction of XML External Entity Reference vulnerability in RTI Connext Professional (Recording Service,Routing Service,Queueing Service,Cloud Discovery Service,Observability Collector) allows Serialized Data External Linking, Data Serialization External Entities Blowup. This issue affects Connext Professional: from 7.4.0 before 7.7.0, from 7.0.0 before 7.3.1.1, from 6.1.0 before 6.1.2.34, from 6.0.0 before 6.0.*, from 5.3.0 before 5.3.*.
A vulnerability exists in RTI Connext Professional's Cloud Discovery Service, Collector Service, Queuing Service, Recording Service, and Routing Service. This vulnerability stems from improper handling of XML external entity references, which can lead to unauthorized access to the local file system and cause a denial-of-service condition by crashing the application. The issue is triggered when the services parse malicious XML configuration documents, a process that can be exploited by providing harmful XML during the application's startup.
Users can protect access to the file system by restricting permissions on XML QoS documents. Additionally, a patch is available for RTI Connext Professional version 7.3.1.2 on the RTI Customer Portal. For other versions, contact RTI Support to arrange a patch.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rti.com/vulnerabilities/#cve-2026-4374 | RTI | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | RTI |
Affected Products
| Product | Versions |
|---|---|
| rti connext professional | >= 5.3.0, <= 5.3.1.45 >= 6.0.0, <= 6.0.1.40 >= 6.1.0, <= 6.1.2.27 >= 7.0.0, < 7.3.1.1 >= 7.4.0, < 7.7.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 22, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | RTI |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 21, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | RTI |