CVE-2026-1879

A vulnerability was detected in Harvard University IQSS Dataverse up to 6.8. This affects an unknown function of the file /ThemeAndWidgets.xhtml of the component Theme Customization. Performing a manipulation of the argument uploadLogo results in unrestricted upload. Remote exploitation of the attack is possible. The exploit is now public and may be used. Upgrading to version 6.10 mitigates this issue. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Configurations

No configuration.

History

01 Apr 2026, 10:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-01 10:16

Updated : 2026-06-17 10:16


NVD link : CVE-2026-1879

Mitre link : CVE-2026-1879

CVE.ORG link : CVE-2026-1879


JSON object : View

Products Affected

No product.

CWE
CWE-284

Improper Access Control

CWE-434

Unrestricted Upload of File with Dangerous Type