PT-2026-4890 · Unknown · Tis-Plugin+1

·

CVE-2026-24815

·

Published

2026-01-27

·

Updated

2026-06-30

CVSS v4.0

10

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/S:P/AU:Y/R:U/V:C/RE:M/U:Red
Name of the Vulnerable Software and Affected Versions datavane tis versions prior to 4.3.0
Description An issue exists in datavane tis related to the unrestricted upload of files with dangerous types and deserialization of untrusted data. The issue is associated with the XmlFile.Java program file within the tis-plugin/src/main/java/com/qlangtech/tis/extension/impl modules.
Recommendations Update to version 4.3.0 or later.

Exploit

Fix

Deserialization of Untrusted Data

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24815

Affected Products

Datavane Tis
Tis-Plugin