Database/Control plane, storage & DevOps

Schneider Electric Data Center Expert - SOAP service endpoints: XML external entity processing on DCE SOAP endpoints
Impact
XML external entity processing on DCE SOAP endpoints lets an authenticated user read server-side files. On a DCIM appliance that means configuration and credential material for the power and cooling estate - the recurring theme with DCE is that any read primitive is a facility-wide credential leak.
Who can reach it
Any user with a DCE account submitting crafted XML to the SOAP endpoints.
What to do
Apply the Schneider fix for DCE. Audit DCE account holders in the same pass. Cheap software update; the credential rotation afterwards is the expensive half.
References
Related entries
- Dell OpenManage Server Administrator (authorization checks): A second, distinct flaw in the same OMSA versionsCVE-2026-81439 · Dell OpenManage Server Administrator (authorization checks)Medium
- Airflow Akeyless provider: path-shaped Variable key bypasses the team-scope guard on secret lookupCVE-2026-86465 · Apache Airflow Akeyless provider (secrets backend, team-scope guard)Medium
- Jenkins Bitbucket Push and Pull Request Plugin: webhook payload can redirect credentialed requestsCVE-2026-92139 · Jenkins Bitbucket Push and Pull Request Plugin (webhook-supplied URLs)Medium
- Airflow HashiCorp provider: path-shaped Variable key crosses team scope in the Vault secrets backendCVE-2026-97636 · Apache Airflow HashiCorp provider (Vault secrets backend, team-scoped variable lookup)Medium
- Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients): Ceph's Python code constructs imaplib.IMAP4_SSL andNCVD-2024-010-ceph-python-bindings-imap4-ssl-s · Ceph (Python bindings, IMAP4_SSL/SMTP_SSL TLS clients)Medium
- rclone (serve s3): Path traversal in rclone's S3 gateway lets a caller read and overwrite files above the served root.NCVD-2026-042-rclone-serve-s3 · rclone (serve s3)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.