PT-2026-56675 · Dspace+2 · Dspace+1

CVE-2026-49830

·

Published

2026-07-08

·

Updated

2026-09-02

CVSS v3.1

4.4

Medium

VectorAV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions DSpace versions prior to 7.6.7 DSpace versions 8.0 through 8.3 DSpace versions 9.0 through 9.2
Description When ingesting an aggregated ORE resource by URI using the OAI-ORE Harvester, the ORE Ingestion Crosswalk fails to validate the URI scheme. This allows an attacker with DSpace collection administrator privileges to perform local file inclusion by providing malicious paths, such as file:///etc/passwd. A remote OAI endpoint configured as a harvest source can supply malicious ORE XML, resulting in local files from the DSpace server being ingested as a bitstream.
Recommendations Update DSpace to version 7.6.7, 8.4, 9.3, or 10.0. As a temporary workaround, disable the ORE ingestion crosswalk in dspace.cfg by removing or commenting out the org.dspace.content.crosswalk.OREIngestionCrosswalk plugin.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49830
GHSA-C827-PW3M-67W7

Affected Products

Dspace
Org.Dspace:Dspace-Api