CVE-2026-84285

An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

  • Published Sep 21, 2026
  • CVSS 8.8 high
  • 1.8% chance of exploitation in the next 30 days (EPSS)

Affected software

CVE-2026-84285 at the National Vulnerability Database