๐Ÿ” CVE Alert

CVE-2026-4813

UNKNOWN 0.0

Code injection in the Lutece Core

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing configuration does not enable secure processing mode (FEATURE_SECURE_PROCESSING), allowing Java extension functions to be executed from malicious XSL stylesheets. An attacker with administrator privileges can upload a manipulated XSL transformation file and trigger its execution during user export operations, resulting in the execution of arbitrary code on the server.

CWE CWE-94
Vendor lutece
Product lutece core
Published Sep 1, 2026
Stay Ahead of the Next One

Get instant alerts for lutece lutece core

Be the first to know when new unknown vulnerabilities affecting lutece lutece core are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Lutece / Lutece Core
0 < 7.1.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
incibe.es: http://incibe.es/en/incibe-cert/notices/aviso/code-injection-lutece-core

Credits

Dorian Piette (Trachinus).