# CVE-2026-84285

An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

**Published**
2026-09-21

**Updated**
-

**Description**
An OS Command Injection vulnerability affecting Tuleap Enterprise Edition from 17.3 through 17.5 could allow an attacker to execute arbitrary commands on the server.

**Affected Products**
Tuleap Enterprise Edition

**Affected Versions**
From 17.3 through 17.5

**Severity**
High

## Go to Dassault Systèmes Security Advisories

[Security Advisories](/trust-center/security/security-advisories)

[   Go to CVE record     ](https://www.cve.org/CVERecord?id=CVE-2026-84285)

[   Access remediation information  ](https://my.enalean.com/plugins/document/tuleap-by-enalean/folder/3616/3686)