CVE-2026-41876: R-Soft Serwis Dms
High severity, CVSS 8.7. EPSS: 1.2% chance of exploitation in the next 30 days.
R-SOFT DMS is vulnerable to OS Command Injection in konwertujAction() function. The document converter executes shell commands using unsanitized file paths and format parameters. This allows an authenticated attacker to execute arbitrary system commands with the privileges of the web server user. This issue was fixed in version v3.19-2752 and v3.17-2580.
Affected products
- R-Soft Serwis Dms: before v3.19-2752 (fixed in v3.19-2752); before v3.17-2580 (fixed in v3.17-2580)
Published 2026-07-10. Last modified 2026-07-10.