CVE-2026-44672

Severity CVSS v4.0:
CRITICAL
Type:
CWE-94 Code Injection
Publication date:
28/05/2026
Last modified:
28/05/2026

Description

mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3.