Path Traversal Vulnerability in DSpace Repository Software
CVE-2026-49833

5.5MEDIUM

Key Information:

Vendor

Dspace

Status
Vendor
CVE Published:
2 September 2026

What is CVE-2026-49833?

A path traversal vulnerability in DSpace allows attackers with administrator credentials to exploit the COAR Notify / LDN service. By manipulating file input streams, an attacker can bypass security checks, leading to potential exposure of sensitive information stored elsewhere in the file system. The issue arises when the LDN class does not properly restrict file access to a designated base path, allowing untrusted files to be interpreted. This vulnerability affects specific versions of DSpace and has been addressed in subsequent updates.

Affected Version(s)

DSpace >= 8.0-rc1, < 8.4 < 8.0-rc1, 8.4

DSpace >= 9.0-rc1, < 9.3 < 9.0-rc1, 9.3

DSpace = 10-rc1 = 10-rc1

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.