If you suspect you have found a security vulnerability in Apache XMLBeans code, please read https://www.apache.org/security/ for how to report the issue. Please do not report the details publicly until the report is reviewed.
We strongly discourage users of Apache XMLBeans from using the library to parse documents from untrusted sources. For more details, please read the Apache POI team's Security Policy at https://poi.apache.org/security.html.