CVE-2026-82918 Details
Description
XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references. If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.
A vulnerability exists in XG VisionTerminal and XG-X VisionTerminal by Keyence Corporation due to improper restriction of XML external entity references. This issue affects XG-X VisionTerminal versions through 3.6.0000 and XG VisionTerminal versions through 5.5.0010. When a user opens a specially crafted setting file, sensitive information stored on the system may be disclosed.
Users of XG-X VisionTerminal should update to version 3.7.0000 or above. Users of XG VisionTerminal should upgrade to XG-X VisionTerminal version 3.7.0000 or above, as XG VisionTerminal is no longer supported. If an immediate update or upgrade is not possible, users are advised not to open untrusted setting files.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 3, 2026CISA-ADP
Assessed Sep 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://jvn.jp/en/vu/JVNVU98062224/index.html | [email protected] | AdvisoryRemedy |
| https://www.keyence.com/mi26082104 | [email protected] | Broken LinkVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Keyence XG VisionTerminal | <= 5.5.0010 (semver) |
CPE
Remediation
| |
| Keyence XG-X VisionTerminal | <= 3.6.0000 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 15, 2026 | CVE Modified | [email protected] |
| Sep 3, 2026 | CVE Modified | CISA-ADP |
| Sep 3, 2026 | New CVE Received | [email protected] |
Volerion