What is CVE-2026-42140?
PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML Macro is vulnerable to Server-Side Request Forgery (SSRF). The macro allows users to specify an alternative PlantUML server via the server parameter. However, the application does not validate the supplied URL. An attacker can supply an internal IP address or a malicious external URL. The XWiki server will attempt to connect to this URL to "render" the diagram. This issue has been patched in version 2.4.1.
Timeline
- 2026-05-04Published to the U.S. National Vulnerability Database (NVD)
- 2026-06-17NVD record last updated
Affected product
See advisory
Remediation Steps
- Upgrade Ruggedcom Rox to version 2.17.1 or later to patch input validation and third-party vulnerabilities
- Disable Scheduler functionality until validated after patching
- Review Scheduler command history logs for evidence of arbitrary command injection attempts
- Restrict Ruggedcom Rox administrative access to authenticated users only via strong MFA
- Conduct operational validation of all critical network routing functions post-upgrade
References
- https://github.com/xwiki-contrib/macro-plantuml/commit/c8b19bda93058794e04c8862fc7ca85c59b5fe5c
- https://github.com/xwiki-contrib/macro-plantuml/security/advisories/GHSA-42fc-7w97-8vrc
- https://jira.xwiki.org/browse/PLANTUML-25
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-134-12.json
- https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-134-16.json
- https://nvd.nist.gov/vuln/detail/CVE-2026-42140
Referenced in our briefings & reports
- Vulnerability Priority Report – Week 3 of May 2026 (May 18 – 24)
Browse all tracked CVEs in the defend.network CVE database →
🤖 This CVE page is generated by defend.network from NVD, CISA KEV, EPSS, and our verified daily briefings. Severity and exploitation data come from official sources; always verify remediation steps against the official vendor advisory before acting in production.