HIGH
OS Command Injection in R-SOFT DMS
Published Jul 10, 2026
8.7
HIGHCVSS 4.0
EPSS 1.23%
Description
R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file paths and format parameters. This allows an authenticated attacker to execute arbitrary system commands with the privileges of the web server user.
This issue was fixed in version v3.19-2752 and v3.17-2580.
Affected products
-
Affected
- ≥ 0, < v3.17-2580
- ≥ 0, < v3.19-2752
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| R-Soft Serwis | DMS | unaffected | Affected
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://cert.pl/posts/2026/07/CVE-2026-41876 third-party-advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42853 Advisory
| Link | Providers | Tags |
|---|---|---|
| https://cert.pl/posts/2026/07/CVE-2026-41876 | third-party-advisory | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-42853 | Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner CERT-PL
Published Jul 10, 2026
Updated Jul 10, 2026
Reserved Apr 22, 2026
Link CVE-2026-41876
CISA Vulnrichment
Updated Jul 10, 2026
Red Hat
No data
GitHub
No data