CVE-2026-19851
7.7Dassault Systèmes · Tuleap Enterprise Edition
Tuleap Enterprise Edition is vulnerable to a use of default password flaw, which may allow unauthorized users to gain administrative access to the platform.
Executive summary
A high severity use of default password vulnerability in Tuleap Enterprise Edition could allow unauthorized actors to gain administrative access to the system.
Vulnerability
The application is susceptible to a use of default password (CWE-1393) vulnerability. This flaw allows an unauthenticated attacker to potentially gain access to the system if the default credentials have not been changed.
Business impact
The presence of default credentials provides an easy path for unauthorized access, which can lead to complete compromise of the Tuleap instance. Given the CVSS score of 7.7, this risk is substantial, as it could lead to the theft of intellectual property, project management data, or other sensitive information hosted on the platform.
Remediation
Immediate Action: Change all default passwords immediately and ensure that all administrative accounts are secured with unique, strong credentials.
Proactive Monitoring: Review system access logs for suspicious login attempts or unauthorized modifications originating from administrative accounts.
Compensating Controls: Implement network-level access controls to restrict exposure of the Tuleap interface to trusted internal networks only.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
Security teams must prioritize the remediation of default account configurations immediately. All instances of Tuleap Enterprise Edition within the affected version range should be audited to ensure that no default passwords remain in use.