A vulnerability was found in opensagres xdocreport up to 2.2.0 and classified as critical. This affects an unknown part of the component Velocity template engine configuration. Such manipulation leads to improper neutralization of special elements used in a template engine.
This vulnerability is traded as CVE-2026-38165. The attack may be launched remotely. There is no exploit available.