Executive brief
R-SOFT DMS, a document management system, contains a security flaw in its Optical Character Recognition (OCR) module. An authenticated user can exploit this flaw to execute unauthorized commands on the underlying server with the highest possible privileges (root). This could lead to a total system takeover, theft of all stored documents, or permanent disruption of the service.
Technical details
R-SOFT DMS is vulnerable to OS command injection within its Optical Character Recognition (OCR) module. The vulnerability exists because multiple functions responsible for command execution accept user-controllable file paths and pass them to the system shell via SSH without adequate sanitization. While standard web upload flows may neutralize the injection via URL encoding, an authenticated attacker who can trigger the OCR process on a specially crafted file path can achieve arbitrary code execution. Successful exploitation grants the attacker root-level privileges on the host system. The issue is resolved in versions v3.19-2862 and v3.17-2580.
Affected products
- R-SOFT SERWIS DMS All versions prior to v3.19-2862 and v3.17-2580
Timeline
- 2026-07-10: advisory: Advisory published by CERT.PL and NVD
- 2026-07-10: patched: Fixes released in versions v3.19-2862 and v3.17-2580