SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-49832

HIGH · CVSS 8 EPSS 0.54% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

DSpace open source software versions 8.0-rc1 to before 8.4, 9.0-rc1 to before 9.3, and 10-rc1 are vulnerable to Remote Code Execution (RCE) due to insecure handling of Velocity Templates in COAR Notify/LDN messages. This vulnerability allows attackers to execute arbitrary code on affected systems, posing a significant risk to data integrity and system security. Organizations using these versions should prioritize patching to the latest releases (8.4, 9.3, or 10.0) to mitigate the threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-49832
Severity
HIGH
CVSS
8
EPSS
0.54%

Original NVD Description

DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before 8.4, versions 9.0-rc1 to before 9.3, and version 10-rc1, Remote Code Execution (RCE) is possible via Velocity Templates used by DSpace for COAR Notify/LDN messages. This issue has been patched in versions 8.4, 9.3, and 10.0.