Description
A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.
Published: 2026-08-25
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to user accounts via default passwords during XML import
Action: Patch Now
AI Analysis

Impact

This vulnerability allows an attacker to leverage default passwords automatically assigned to accounts created through XML import in Tuleap Enterprise Edition. The weakness is identified as CWE-1393, which involves the use of a default or negligible password, enabling credential compromise. If an attacker can obtain the default credentials, they can log in to the affected accounts and potentially access or modify sensitive data, increasing both confidentiality and integrity risk.

Affected Systems

Dassault Systèmes' Tuleap Enterprise Edition is affected from version 17.0 through 17.5. Any installation within this version range that performs XML import operations will expose new user accounts with a default password. Older or newer releases are not impacted according to the current CNA data.

Risk and Exploitability

The CVSS base score of 7.7 indicates a high severity. EPSS is not reported, and the vulnerability is not listed in CISA KEV, suggesting it is not widely exploited yet. The likely attack vector is the XML import process itself, where an attacker who can either supply an import file or who knows the default password can bypass authentication. Successful exploitation results in unauthorized access to user accounts created by the import, potentially giving an attacker full privileges within the Tuleap instance.

Generated by OpenCVE AI on August 25, 2026 at 09:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Tuleap Enterprise Edition to a release that eliminates default passwords for imported accounts or apply the vendor’s available patch
  • Immediately change the passwords for all accounts created during XML import to strong, unique values
  • Restrict or disable XML import functionality for unauthenticated or low‑privilege users to reduce exposure
  • Conduct a credential audit to identify any remaining accounts that may use the default password and remediate them

Generated by OpenCVE AI on August 25, 2026 at 09:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Dassault Systèmes
Dassault Systèmes tuleap Enterprise Edition
Vendors & Products Dassault Systèmes
Dassault Systèmes tuleap Enterprise Edition

Tue, 25 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Description A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.
Title Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5
Weaknesses CWE-1393
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L'}


Subscriptions

Dassault Systèmes Tuleap Enterprise Edition
cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-08-25T14:51:55.235Z

Reserved: 2026-08-14T09:19:34.760Z

Link: CVE-2026-19851

cve-icon Vulnrichment

Updated: 2026-08-25T14:46:31.344Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-25T08:18:08.880

Modified: 2026-08-28T15:42:20.060

Link: CVE-2026-19851

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T10:00:09Z

Weaknesses