CVE-2026-19851: Dassault Systèmes Tuleap Enterprise Edition

High severity, CVSS 7.7. EPSS: 0.2% chance of exploitation in the next 30 days.

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.

Affected products

  • Dassault Systèmes Tuleap Enterprise Edition: from 17.0-1, up to and including 17.0-36; from 17.5-1, up to and including 17.5-24

Published 2026-08-25. Last modified 2026-08-28.