Remote Code Execution Vulnerability in Lutece Core Export Management Module
CVE-2026-4813
9.4CRITICAL
What is CVE-2026-4813?
A vulnerability in the Lutece Core XSL export management module allows authenticated administrators to execute arbitrary code remotely due to the absence of secure processing mode in XML/XSLT processing configuration. Attackers with administrator privileges can exploit this flaw by uploading a crafted XSL transformation file, leading to the execution of malicious Java extensions during user export operations. This poses a significant risk to server integrity and data security.
Affected Version(s)
Lutece Core 0 < 7.1.7
