Remote Code Execution Vulnerability in DSpace Repository Software
CVE-2026-49832

8HIGH

Key Information:

Vendor

Dspace

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-49832?

A vulnerability exists in DSpace open source software, a popular repository application utilized for accessing digital resources. This issue allows remote code execution through the exploitation of Velocity Templates utilized for COAR Notify/LDN messages. The vulnerability affects DSpace versions from 8.0-rc1 to prior to 8.4, 9.0-rc1 to prior to 9.3, and 10-rc1. Fortunately, this flaw has been addressed in the patched versions 8.4, 9.3, and 10.0, making it imperative for users to upgrade to these versions to secure their systems.

Affected Version(s)

DSpace >= 8.0-rc1, < 8.4 < 8.0-rc1, 8.4

DSpace >= 9.0-rc1, < 9.3 < 9.0-rc1, 9.3

DSpace = 10-rc1 = 10-rc1

References

CVSS V3.1

Score:
8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.