PT-2026-57149 · Unknown · R-Soft Dms

·

CVE-2026-41880

·

Published

2026-07-10

·

Updated

2026-07-10

CVSS v4.0

9.0

Critical

VectorAV:N/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions R-SOFT DMS versions prior to v3.19-2862 R-SOFT DMS versions prior to v3.17-2580
Description The Optical Character Recognition (OCR) module contains an OS Command Injection flaw. Multiple command execution functions process user-controllable file paths without adequate sanitization before they are passed to the system shell via SSH. While URL encoding prevents this during standard web uploads, an authenticated attacker can execute operating system commands with root privileges by triggering the OCR functionality for an uploaded file.
Recommendations Update to version v3.19-2862 or later. Update to version v3.17-2580 or later. Restrict access to the OCR module to minimize the risk of exploitation.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41880

Affected Products

R-Soft Dms