Junglewise Threat Intelligence

CVE-2026-41876: R-SOFT DMS OS command injection in konwertujAction

CVE-2026-41876 · Severity: info · CVSS 8.7 · Published 2026-07-10

Technologies: R-SOFT SERWIS DMS. Vendors: R-SOFT SERWIS.

Executive brief

R-SOFT DMS, a document management system, contains a security flaw in its document conversion tool. An authorized user can exploit this to run unauthorized commands on the underlying server. This could lead to a complete system takeover, unauthorized data access, or disruption of business operations.

Technical details

An OS Command Injection vulnerability exists in the konwertujAction() function of R-SOFT DMS. The document converter component fails to properly sanitize user-supplied file paths and format parameters before passing them to shell execution commands. An authenticated attacker can exploit this by providing specially crafted input to execute arbitrary system commands with the privileges of the web server user. The vulnerability is addressed in versions v3.19-2752 and v3.17-2580.

Affected products

  • R-SOFT SERWIS DMS Versions prior to v3.19-2752 and v3.17-2580

Timeline

  • 2026-07-10: advisory: Initial advisory published by CERT.PL and NVD
  • 2026-07-10: patched: Fixes released in versions v3.19-2752 and v3.17-2580

References

Related threats