Executive brief
Tuleap Enterprise Edition is a collaborative platform for managing projects and software development. An OS command injection vulnerability in versions 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server, potentially leading to complete system compromise, data theft, or service disruption.
Technical details
An OS command injection vulnerability exists in Tuleap Enterprise Edition that permits an attacker to inject and execute arbitrary OS commands on the affected server. The vulnerability affects versions 17.3 through 17.5 and likely requires some form of user interaction or authentication based on typical Tuleap architecture. Successful exploitation results in remote code execution with the privileges of the application process.
Affected products
- Dassault Systèmes Tuleap Enterprise Edition 17.3 through 17.5
Timeline
- 2026-09-21: disclosed