SB2026012277 - Confluence Data Center and Server update for org.apache.jackrabbit:jackrabbit-spi-commons
Published: January 22, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Blind XML External Entity injection (CVE-ID: CVE-2025-53689)
The vulnerability allows a remote user to alter application's behavior.
The vulnerability exists due to insufficient validation of user-supplied XML input in jackrabbit-spi-commons and jackrabbit-core components. A remote user can pass a specially crafted XML code to the affected application and escalate their privileges.
Remediation
Install update from vendor's website.