Code injection in the Lutece Core

Posted date 01/09/2026
Identificador
INCIBE-2026-595
Importance
5 - Critical
Affected Resources

Lutece Core: version 7.1.7 and earlier.

Description

INCIBE has coordinated the disclosure of a critical-severity vulnerability in Lutece Core, an open platform that enables local authorities to share, reuse and adapt digital services. The vulnerability was discovered by Dorian Piette (Trachinus).

This vulnerability has been assigned the following code, CVSS v4.0 base score, CVSS vector and CWE vulnerability type:

  • CVE-2026-4813: CVSS v4.0: 9.4 | CVSS AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H | CWE-94
Solution

The manufacturer has released the patch (v7.1.9).

Detail

CVE-2026-4813: a vulnerability in the Lutece Core XSL export management module up to version 7.1.7, which allows authenticated administrators to execute code remotely. The XML/XSLT processing configuration does not enable secure processing mode (FEATURE_SECURE_PROCESSING), allowing Java extension functions to be executed from malicious XSL stylesheets. An attacker with administrator privileges can upload a manipulated XSL transformation file and trigger its execution during user export operations, resulting in the execution of arbitrary code on the server.

CVE
Identificador CVE Severidad Explotación Fabricante
CVE-2026-4813 Crítica No Lutece
References list
Etiquetas