[Japanese]

JVNDB-2026-031532

Improper restriction of XML external entity reference in XG VisionTerminal and XG-X VisionTerminal

Overview

XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation contain the following vulnerability.
  • Improper restriction of XML external entity reference (CWE-611) - CVE-2026-82918
Michael Heinzl reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 5.5 (Medium) [Other]
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: Required
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: None
  • Availability Impact: None
Affected Products


KEYENCE CORPORATION.
  • XG VisionTerminal Ver.5.5.0010 and earlier
  • XG-X VisionTerminal Ver.3.6.0000 and earlier

As for the details of how to check the versions, refer to the information provided by the developer.
Impact

If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.
Solution

[Update the software]
Update XG-X VisionTerminal to the version above Ver.3.7.0000.

[Upgrade to alternative software]
The developer recommends that the users of XG VisionTerminal should upgrade to XG-X VisionTerminal Ver.3.7.0000 or above since XG VisionTerminal is EOL (end-of-life), therefore no longer supported.

[Apply workaround]
The developer recommends that the users should apply following workaround if applying immediate update or upgrade is difficult.
  • Do not open untrusted setting files
For more information, refer to the information provided by the developer.
Vendor Information

KEYENCE CORPORATION.
CWE (What is CWE?)

  1. Improper Restriction of XML External Entity Reference(CWE-611) [Other]
CVE (What is CVE?)

  1. CVE-2026-82918
References

  1. JVN : JVNVU#98062224
Revision History

  • [2026/09/03]
      Web page was published