---
cve: "CVE-2026-15037"
severity: "LOW"
cvss: 2.9
epss: "0.4%"
vendor: "Qt"
kev: false
exploited: false
published: "2026-07-23 13:16:25"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-10-02T18:12:11+02:00"
---

# CVE-2026-15037

> 2.9 LOW

## Beschreibung

Improper output neutralization (XML injection) in QDom comment, CDATA, and processing-instruction serialization in Qt XML from 4.0.0 through 6.11 allows untrusted text serialized by an application into those nodes to inject arbitrary XML markup, because the node terminators are not escaped under the default InvalidDataPolicy (AcceptInvalidChars). Fixed in Qt 6.12.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **no**
  - Technical Impact: **partial**

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |

## BSI-Hinweise (deutsch)

- [QT: Schwachstelle ermöglicht Manipulation von Dateien](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2026-2500) — _BSI-Einstufung: mittel_
  Ein entfernter, anonymer Angreifer kann eine Schwachstelle in QT ausnutzen, um Dateien zu manipulieren.

## Referenzen

- <https://codereview.qt-project.org/c/qt/qtbase/+/748323>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-15037) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
