CVE-2025-36603: Dell Appsync

Medium severity, CVSS 4.8. EPSS: 0.1% chance of exploitation in the next 30 days.

Dell AppSync, version(s) 4.6.0.0, contains an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure and Information tampering.

Affected products

  • Dell Appsync: before 4.6.0.4 (fixed in 4.6.0.4)

Published 2025-07-21. Last modified 2026-06-17.