PT-2026-56677 · Dspace+2 · Dspace+1

CVE-2026-49832

·

Published

2026-07-08

·

Updated

2026-09-02

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions DSpace versions 8.0-rc1 through 8.3 DSpace versions 9.0-rc1 through 9.2 DSpace version 10-rc1
Description Remote Code Execution (RCE) is possible via Velocity Templates used for COAR Notify/LDN messages. An attacker with DSpace administrator credentials can execute Java directly from Velocity templates using reflection, especially when chained with a path traversal attack. Velocity is also used for email templating, and while no attack path via emails is known, the fix applies to them as well.
Recommendations Update DSpace versions 8.0-rc1 through 8.3 to version 8.4. Update DSpace versions 9.0-rc1 through 9.2 to version 9.3. Update DSpace version 10-rc1 to version 10.0. As a temporary workaround, disable LDN by setting ldn.enabled=false in dspace.cfg or local.cfg.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49832
GHSA-9X82-RM84-C6X7

Affected Products

Dspace
Org.Dspace:Dspace-Api