CVE-2026-44672
mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dynamic table without being authenticated. This vulnerability is fixed in 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3.
Published:May 28, 2026
Last Modified:May 29, 2026
EPS:May 28, 2026
EPSS Score:0.00078
CVSS Score:9.3
Affected Products
Vendor
Product
Action
Vendor
Camptocamp
Product
Mapfish Print
Camptocamp
Mapfish Print
Vendor
Mapfish
Product
Mapfish-print
Mapfish
Mapfish-print
Vendor
Org.mapfish
Product
Print.print-lib
Org.mapfish
Print.print-lib
Vendor
Org.mapfish
Product
Print.print-servlet
Org.mapfish
Print.print-servlet
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
