Executive brief
Tuleap Enterprise Edition is a collaborative software development platform used by organizations to manage projects and source code. A default password vulnerability in versions 17.0 through 17.5 affects user accounts created during XML import, allowing attackers with knowledge of the default credentials to gain unauthorized access to these accounts without proper authentication.
Technical details
This is a Use of Default Password vulnerability (CWE-1392) in Tuleap Enterprise Edition affecting the XML import functionality. User accounts created through the XML import process in versions 17.0 through 17.5 are initialized with default credentials instead of unique or randomly-generated passwords. An attacker can exploit this by using the known default credentials to authenticate as any XML-imported user account, bypassing normal authentication controls. The vulnerability requires network access to the Tuleap instance and knowledge of the default password, but no user interaction or prior authentication is required. Patches are available in versions after 17.5.
Affected products
- Dassault Systèmes Tuleap Enterprise Edition 17.0 through 17.5
Timeline
- 2026-08-25: disclosed
- 2026-08-25: advisory