
🚨Critical - Mapfish Print Remote Code Injection (CVE-2026-44672) A critical flaw in dynamic table generation allows unauthenticated attackers to supply crafted external inputs that are improperly neutralized and executed as system code. This directly enables remote code execution (RCE), granting attackers immediate and full control over the compromised server. 👉 Affected: versions <=3.23.0, < 4.0.3 | Upgrade to 3.28.28, 3.30.30, 3.31.21, 3.33.14, 4.0.3
Post summary
A critical remote code injection flaw (CVE‑2026‑44672) in Mapfish Print allows unauthenticated RCE; affected releases are <=3.23.0 and <4.0.3, with recommended upgrades to the listed versions.
