PT-2026-84142 · Unknown · Lutece Core

CVE-2026-4813

·

Published

2026-09-01

·

Updated

2026-09-03

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Lutece Core versions prior to 7.1.8
Description An issue in the XSL export management module allows authenticated administrators to execute arbitrary code on the server. The XML/XSLT processing configuration fails to enable secure processing mode (FEATURE SECURE PROCESSING), which permits the execution of Java extension functions via malicious XSL stylesheets. An attacker with administrator privileges can upload a manipulated XSL transformation file and trigger its execution during user export operations.
Recommendations Update Lutece Core to version 7.1.8 or later.

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4813

Affected Products

Lutece Core