Subject: XPressEntry security update: action needed for customers on builds prior to 3.7.7699
Date: 9/15/2026
In August 2026, a third-party research group published an advisory describing a SQL injection vulnerability in the XPressEntry API, together with proof-of-concept code. You may view the report here.
For an attack to occur, one of two things need to be true for a customer installation:
- XPressEntry login information is not secure, including the use of default credentials.
- Customers have manually disabled “Use Credentials”, from the default setting.
As with most hacks, misconfiguring a system increases the attack surface for hackers, but regardless we want our software to be secure and safe. The day after we were alerted of the advisory, we shipped an update that remediated the problem.
The large majority of deployments were never exposed, because exploitation requires a configuration that XPressEntry does not ship. To this end, we have had no reports or indications of exploitation in the field.
To best protect systems in the field please do the following:
- Upgrade XPressEntry. Download the latest version from https://telaeris.com/downloads. This is supported for anyone on maintenance.
- Confirm that reader credential checking is enabled in XPressEntry.
(Tools → Settings → Server → Service Settings → Use Credentials for all Readers) - Ensure XPressEntry is not using default credentials.
Other good IT suggestions we recommend include:
- Restrict network access to the XPressEntry Server to known reader endpoints.
- Run the XPressEntry SQL Server login as a non-sysadmin account.
- Disable xp_cmdshell on the SQL Server instance.
Please reach out to us at https://telaeris.com/helpdesk/ if you find any deployments with the above vulnerabilities exposed OR if you support a customer in a government, critical-infrastructure or otherwise regulated environment with contractual notification obligations.