Junglewise Threat Intelligence

CVE-2026-49833: DSpace open source software is a repository application which provides durable access to digital resources. From versions 8.0-rc1 to before

CVE-2026-49833 · Severity: medium · CVSS 5.5 · Published 2026-09-02

Technologies: Dspace.

Executive brief

DSpace is an open-source platform used by organizations to manage and preserve digital research and scholarly content. A security flaw in its notification service allows an administrator to access unauthorized files on the server. In a worst-case scenario, this could be used to steal sensitive data or take full control of the server by executing malicious code.

Technical details

A path traversal vulnerability exists in the COAR Notify / LDN service of DSpace due to insufficient validation of 'inbound pattern' or 'template' names. The LDN class fails to restrict template file paths to the expected base directory ($dspace.dir/config/ldn), allowing an attacker with DSpace administrator credentials to reference arbitrary files on the filesystem. If an attacker can place a malicious Apache Velocity payload in a predictable location (such as a log file), they can use this vulnerability to include that file as a template, leading to information disclosure or remote code execution. The vulnerability is patched in versions 8.4, 9.3, and 10.0.

Affected products

  • DSpace DSpace >= 8.0-rc1, <= 8.3, >= 9.0-rc1, <= 9.2, 10.0-rc1

Timeline

  • 2026-06-01: disclosed
  • 2026-07-08: advisory

References