CVE-2026-19851

7.7

Dassault Systèmes · Tuleap Enterprise Edition

Tuleap Enterprise Edition is vulnerable to a use of default password flaw, which may allow unauthorized users to gain administrative access to the platform.

Executive summary

A high severity use of default password vulnerability in Tuleap Enterprise Edition could allow unauthorized actors to gain administrative access to the system.

Vulnerability

The application is susceptible to a use of default password (CWE-1393) vulnerability. This flaw allows an unauthenticated attacker to potentially gain access to the system if the default credentials have not been changed.

Business impact

The presence of default credentials provides an easy path for unauthorized access, which can lead to complete compromise of the Tuleap instance. Given the CVSS score of 7.7, this risk is substantial, as it could lead to the theft of intellectual property, project management data, or other sensitive information hosted on the platform.

Remediation

Immediate Action: Change all default passwords immediately and ensure that all administrative accounts are secured with unique, strong credentials.

Proactive Monitoring: Review system access logs for suspicious login attempts or unauthorized modifications originating from administrative accounts.

Compensating Controls: Implement network-level access controls to restrict exposure of the Tuleap interface to trusted internal networks only.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Security teams must prioritize the remediation of default account configurations immediately. All instances of Tuleap Enterprise Edition within the affected version range should be audited to ensure that no default passwords remain in use.

More Dassault Systèmes CVEs