CVE-2026-36765
High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.
An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.
Published 2026-04-30. Last modified 2026-06-17.