Published:2026/09/02  Last Updated:2026/09/02

JVNVU#98062224
Improper restriction of XML external entity reference in XG VisionTerminal and XG-X VisionTerminal

Overview

XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation improperly restrict XML external entity references.

Products Affected

  • XG-X VisionTerminal Ver.3.6.0000 and earlier
  • XG VisionTerminal Ver.5.5.0010 and earlier
As for the details of how to check the versions, refer to the information provided by the developer.

Description

XG VisionTerminal and XG-X VisionTerminal provided by Keyence Corporation contain the following vulnerability.

  • Improper restriction of XML external entity reference (CWE-611)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N Base Score 6.7
    • CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N Base Score 5.5
    • CVE-2026-82918

Impact

If a user opens a specially crafted setting file, the sensitive information stored in the system where XG VisionTerminal or XG-X VisionTerminal is installed may be disclosed.

Solution

Update the software
Update XG-X VisionTerminal to the version above Ver.3.7.0000.

Upgrade to alternative software
The developer recommends that the users of XG VisionTerminal should upgrade to XG-X VisionTerminal Ver.3.7.0000 or above since XG VisionTerminal is EOL (end-of-life), therefore no longer supported.

Apply workaround
The developer recommends that the users should apply following workaround if applying immediate update or upgrade is difficult.

  • Do not open untrusted setting files

For more information, refer to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

Michael Heinzl reported these vulnerabilities to JPCERT/CC.
JPCERT/CC coordinated with the developer.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-82918
JVN iPedia