criticalVulnerability
CVE-2026-44672
### Impact The attacker can execute arbitrary code without being authenticated ### Mitigation Upgrade to a patched version (please check affected/patched version matrix) ### Credits Bug Bounty of Canton du Jura
Properties
- ghsa_id
- GHSA-q7m6-wpvf-mvwx
- severity
- critical
- summary
- Mapfish Print: Remote Code Injection (RCE) in Dynamic table
- epss_score
- 0.00325
- cve_id
- CVE-2026-44672
- is_ghsa_only
- false
- ghsa_published
- 2026-05-13T01:35:37Z
- source_url
- https://github.com/advisories/GHSA-q7m6-wpvf-mvwx
- epss_percentile
- 0.25034
- ghsa_updated
- 2026-05-13T01:35:39Z
Related Entities (7)
ENRICHED_BY (1)
→[Source]FIRST EPSS
VULNERABLE_TO (2)
←[Software]maven/org.mapfish.print:print-lib
←[Software]maven/org.mapfish.print:print-servlet
AFFECTS (2)
→[Software]maven/org.mapfish.print:print-servlet
→[Software]maven/org.mapfish.print:print-lib
HAS_WEAKNESS (1)
→[Weakness]Improper Control of Generation of Code ('Code Injection')
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph