PT-2026-84142 · Unknown · Lutece Core
CVE-2026-4813
·
Published
2026-09-01
·
Updated
2026-09-03
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Lutece Core versions prior to 7.1.8
Description
An issue in the XSL export management module allows authenticated administrators to execute arbitrary code on the server. The XML/XSLT processing configuration fails to enable secure processing mode (
FEATURE SECURE PROCESSING), which permits the execution of Java extension functions via malicious XSL stylesheets. An attacker with administrator privileges can upload a manipulated XSL transformation file and trigger its execution during user export operations.Recommendations
Update Lutece Core to version 7.1.8 or later.
Fix
RCE
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Lutece Core