SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-41876

HIGH · CVSS 8.7 EPSS 0.83%

Source: NVD + CISA KEV + EPSS · Published 2026-07-10 · Last synced 2026-08-09

CyberRota Analysis

AI-Generated

R-SOFT DMS is susceptible to OS Command Injection through the konwertujAction() function, where unsanitized file paths and format parameters enable authenticated attackers to execute arbitrary commands with the web server's privileges. Organizations using affected versions should prioritize remediation to prevent potential exploitation, which could lead to unauthorized access and system compromise. Users should upgrade to version v3.19-2752 or v3.17-2580 to mitigate this vulnerability.

CVE
CVE-2026-41876
Severity
HIGH
CVSS
8.7
EPSS
0.83%

Original NVD Description

R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file paths and format parameters. This allows an authenticated attacker to execute arbitrary system commands with the privileges of the web server user. This issue was fixed in version v3.19-2752 and v3.17-2580.