Remote Code Execution Vulnerability in Document Merge Service by Adfinis
CVE-2026-53964

7.2HIGH

Key Information:

Vendor

Adfinis

Vendor
CVE Published:
1 October 2026

What is CVE-2026-53964?

The Document Merge Service offered by Adfinis is susceptible to a remote code execution flaw caused by server-side template injection. This vulnerability affects versions prior to 9.1.0 and allows an attacker to execute user-supplied code within the context of the server, utilizing the UID 901 for the document-merge-server user. Specifically, the issue arises when processing XLSX templates through the npn-sandboxed Jinja environment, offering substantial control to potential attackers over the server's functionality. Users are advised to upgrade to version 9.1.0 to mitigate this risk.

Affected Version(s)

document-merge-service < 9.1.0

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.