Remote Code Execution Vulnerability in DSpace Repository Software
CVE-2026-49832
8HIGH
What is CVE-2026-49832?
A vulnerability exists in DSpace open source software, a popular repository application utilized for accessing digital resources. This issue allows remote code execution through the exploitation of Velocity Templates utilized for COAR Notify/LDN messages. The vulnerability affects DSpace versions from 8.0-rc1 to prior to 8.4, 9.0-rc1 to prior to 9.3, and 10-rc1. Fortunately, this flaw has been addressed in the patched versions 8.4, 9.3, and 10.0, making it imperative for users to upgrade to these versions to secure their systems.
Affected Version(s)
DSpace >= 8.0-rc1, < 8.4 < 8.0-rc1, 8.4
DSpace >= 9.0-rc1, < 9.3 < 9.0-rc1, 9.3
DSpace = 10-rc1 = 10-rc1
