Remote Code Execution Vulnerability in Document Merge Service by Adfinis
CVE-2026-53964
7.2HIGH
What is CVE-2026-53964?
The Document Merge Service offered by Adfinis is susceptible to a remote code execution flaw caused by server-side template injection. This vulnerability affects versions prior to 9.1.0 and allows an attacker to execute user-supplied code within the context of the server, utilizing the UID 901 for the document-merge-server user. Specifically, the issue arises when processing XLSX templates through the npn-sandboxed Jinja environment, offering substantial control to potential attackers over the server's functionality. Users are advised to upgrade to version 9.1.0 to mitigate this risk.
Affected Version(s)
document-merge-service < 9.1.0
