SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-49831

MEDIUM · CVSS 5.5 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The DSpace open source software is vulnerable due to a Path Traversal issue in the Curation Task feature, allowing unauthorized access to any writable path by the 'tomcat' user through the output path parameter. This could lead to unauthorized file manipulation or exposure of sensitive information. Organizations using affected versions should prioritize updating to versions 7.6.7, 8.4, 9.3, or 10.0 to mitigate potential risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49831
Severity
MEDIUM
CVSS
5.5
EPSS
0.35%

Original NVD Description

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, the Curation Task feature allows an output path to be used by the reporter (-r parameter), typically used to stream results and status of curation task operations. It is not restricted to any particular base path, meaning that any path writable by the DSpace (often 'tomcat') user is allowed. This constitutes a Path Traversal Vulnerability in the curate script. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.