criticalVulnerability

CVE-2026-44672

### Impact The attacker can execute arbitrary code without being authenticated ### Mitigation Upgrade to a patched version (please check affected/patched version matrix) ### Credits Bug Bounty of Canton du Jura

Properties

ghsa_id
GHSA-q7m6-wpvf-mvwx
severity
critical
summary
Mapfish Print: Remote Code Injection (RCE) in Dynamic table
epss_score
0.00325
cve_id
CVE-2026-44672
is_ghsa_only
false
ghsa_published
2026-05-13T01:35:37Z
source_url
https://github.com/advisories/GHSA-q7m6-wpvf-mvwx
epss_percentile
0.25034
ghsa_updated
2026-05-13T01:35:39Z

Related Entities (7)

ENRICHED_BY (1)

[Source]FIRST EPSS

VULNERABLE_TO (2)

[Software]maven/org.mapfish.print:print-lib
[Software]maven/org.mapfish.print:print-servlet

AFFECTS (2)

[Software]maven/org.mapfish.print:print-servlet
[Software]maven/org.mapfish.print:print-lib

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

REPORTED_BY (1)

[Source]GitHub Advisory Database

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-44672 — Ninja Signal Threat Intelligence | Ninja Signal