Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
The manufacturer has released the patch (v7.1.9).
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing configuration does not enable secure processing mode (FEATURE_SECURE_PROCESSING), allowing Java extension functions to be executed from malicious XSL stylesheets. An attacker with administrator privileges can upload a manipulated XSL transformation file and trigger its execution during user export operations, resulting in the execution of arbitrary code on the server. | |
| Title | Code injection in the Lutece Core | |
| First Time appeared |
Lutece
Lutece lutece Core |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:lutece:lutece_core:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Lutece
Lutece lutece Core |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2026-09-01T12:17:12.913Z
Reserved: 2026-03-25T13:08:57.318Z
Link: CVE-2026-4813
No data.
Status : Received
Published: 2026-09-01T11:16:44.443
Modified: 2026-09-01T11:16:44.443
Link: CVE-2026-4813
No data.
OpenCVE Enrichment
Updated: 2026-09-01T12:30:04Z
-
CWE-94
Improper Control of Generation of Code ('Code Injection')