MEDIUM
DSpace
CVE published 2026-09-02
CVE-2026-49830
DSpace open source software is vulnerable to local file inclusion via malicious paths like file:///etc/passwd when ingesting an aggregated ORE resource by URI. The attacker MUST already have DSpace collection administrator privileges in order to perform the attack. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0. Affected administrators should prioritize patching to prevent potential loc [truncated]