CVE-2026-44672

CRITICAL

mapfish-print: Remote Code Injection (RCE) in Dynamic table

Title source: cna
STIX 2.1

Description

mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3.

References (1)

Core 1
Core References

Scores

CVSS v4 9.3
EPSS 0.0032
EPSS Percentile 24.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (30)
camptocamp/mapfish_print >= 3.23.0, < 3.28.28
camptocamp/mapfish_print >= 3.29.0, < 3.30.30
camptocamp/mapfish_print >= 3.31.0, < 3.31.21
camptocamp/mapfish_print >= 3.32.0, < 3.33.14
camptocamp/mapfish_print >= 3.34.0, < 4.0.3
mapfish/mapfish-print >= 3.23.0, < 3.28.28
mapfish/mapfish-print >= 3.29.0, < 3.30.30
mapfish/mapfish-print >= 3.31.0, < 3.31.21
mapfish/mapfish-print >= 3.32.0, < 3.33.14
mapfish/mapfish-print >= 3.34.0, < 4.0.3
... and 20 more
Published May 28, 2026
Tracked Since May 28, 2026