CVE-2026-19851
Received Received - Intake

Use of Default Password in Tuleap Enterprise Edition

Vulnerability report for CVE-2026-19851, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-25

Assigner: Dassault Systèmes

Description

A Use of Default Password vulnerability affecting Tuleap Enterprise Edition from 17.0 through 17.5 could allow an attacker to gain access to user accounts created during XML import.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-25
Generated
2026-08-25
AI Q&A
2026-08-25
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
tuleap tuleap_enterprise_edition From 17.0 (inc) to 17.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1393 The product uses default passwords for potentially critical functionality.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Use of Default Password issue in Tuleap Enterprise Edition versions 17.0 through 17.5. It allows attackers to gain unauthorized access to user accounts that were created during XML import processes due to default or weak passwords being used.

Impact Analysis

An attacker could exploit this to gain access to user accounts, potentially leading to data breaches, unauthorized modifications, or theft of sensitive information stored in those accounts.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR or HIPAA by enabling unauthorized access to personal or health data, resulting in legal penalties, fines, or reputational damage due to data breaches.

Mitigation Strategies

Update Tuleap Enterprise Edition to a version beyond 17.5 to address the default password issue in XML-imported user accounts.

Review and change any default passwords for accounts created during XML imports to strong, unique passwords.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-19851. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart