CVE-2026-84285

Summary

An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

Affected Software

VendorProductVersion RangeStatus
Dassault SystèmesTuleap Enterprise Edition17.3-1 <= 17.3-12affected
Dassault SystèmesTuleap Enterprise Edition17.5-1 <= 17.5-28affected

Weaknesses

  • CWE-78: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References