{"id":"CVE-2026-84285","published":"2026-09-21T13:17:10.830","lastModified":"2026-09-21T20:17:36.700","description":"An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-78"],"vendors":[],"products":[],"references":[{"url":"https://www.3ds.com/trust-center/security/security-advisories/cve-2026-84285","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is an OS Command Injection vulnerability in Tuleap Enterprise Edition from versions 17.3 to 17.5, allowing attackers to execute arbitrary commands on the server, posing a significant security risk.","exploitability":"Exploitation requires access to the affected version of Tuleap and knowledge of the specific input vectors; however, once compromised, it can be relatively straightforward due to the high CVSS score.","blast_radius":"If exploited, this vulnerability could lead to complete server compromise, data theft, and potential lateral movement within the network.","remediation":"Upgrade Tuleap Enterprise Edition to a non-affected version immediately or apply vendor-provided patches.","tags":["rce","web","server","vulnerability"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:03:51.819Z"}}