A vulnerability classified as critical has been found in Datavane TIS up to 5.0.0. This impacts the function edit_workflow of the component DocumentBuilderFactory. This manipulation of the argument taskScript causes xml external entity reference.

This vulnerability is registered as CVE-2026-69101. Remote exploitation of the attack is possible. No exploit is available.