Medium severity4.4NVD Advisory· Published Oct 5, 2026
CVE-2026-101893
CVE-2026-101893
Description
Newell Brands DYMO ID 1.5.1.71 parses job files using XmlDocument.Load() without disabling DTD processing. The PC Job Files view automatically parses every recognized job file extension on folder browse. A crafted file on any browsed network share can perform SSRF, capture NTLMv2 credentials, read local files, or crash the process. Fixed in 1.6.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.6.0
Patches
Vulnerability mechanics
References
4News mentions
0No linked articles in our index yet.