CVE-2026-49830

DSpace open source software is a repository application which provides durable access to digital resources. Prior to versions 7.6.7, 8.4, 9.3, and 10.0, when ingesting an aggregated ORE resource by URI (using the OAI-ORE Harvester), the ORE Ingestion Crosswalk does not validate the URI scheme. This may allow for local file inclusion via malicious paths like file:///etc/passwd. The attacker MUST already have DSpace collection administrator privileges in order to perform the attack. This issue has been patched in versions 7.6.7, 8.4, 9.3, and 10.0.

  • Published Sep 2, 2026
  • CVSS 4.4 medium
  • 0.5% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-49830 at the National Vulnerability Database