PT-2026-56677 · Dspace+2 · Dspace+1
CVE-2026-49832
·
Published
2026-07-08
·
Updated
2026-09-02
CVSS v3.1
8.0
High
| Vector | AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
DSpace versions 8.0-rc1 through 8.3
DSpace versions 9.0-rc1 through 9.2
DSpace version 10-rc1
Description
Remote Code Execution (RCE) is possible via Velocity Templates used for COAR Notify/LDN messages. An attacker with DSpace administrator credentials can execute Java directly from Velocity templates using reflection, especially when chained with a path traversal attack. Velocity is also used for email templating, and while no attack path via emails is known, the fix applies to them as well.
Recommendations
Update DSpace versions 8.0-rc1 through 8.3 to version 8.4.
Update DSpace versions 9.0-rc1 through 9.2 to version 9.3.
Update DSpace version 10-rc1 to version 10.0.
As a temporary workaround, disable LDN by setting
ldn.enabled=false in dspace.cfg or local.cfg.Exploit
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Dspace
Org.Dspace:Dspace-Api