PatchSiren

DSpace CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM DSpace CVE published 2026-09-02

CVE-2026-49830

DSpace open source software is vulnerable to local file inclusion via malicious paths like file:///etc/passwd when ingesting an aggregated ORE resource by URI. The attacker MUST already have DSpace collection administrator privileges in order to perform the attack. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0. Affected administrators should prioritize patching to prevent potential loc [truncated]