{"id":"CVE-2026-84839","summary":"tsi-coop tsi-dpdp-cms Admin Console/DPO Compliance Console web.xml missing authentication","details":"A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is some unknown functionality of the file web.xml of the component Admin Console/DPO Compliance Console. Executing a manipulation can lead to missing authentication. It is possible to launch the attack remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.5.1 can resolve this issue. It is suggested to upgrade the affected component.","modified":"2026-09-04T08:02:29.766929Z","published":"2026-09-02T18:15:11.525Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-287","CWE-306"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84839.json"},"references":[{"type":"WEB","url":"https://github.com/tsi-coop/tsi-dpdp-cms/"},{"type":"WEB","url":"https://github.com/tsi-coop/tsi-dpdp-cms/blob/main/docs/security-fixes/3.md"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/84xxx/CVE-2026-84839.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-84839"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-84839"},{"type":"ADVISORY","url":"https://vuldb.com/submit/885619"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/398081"},{"type":"REPORT","url":"https://vuldb.com/vuln/398081/cti"},{"type":"FIX","url":"https://github.com/tsi-coop/tsi-dpdp-cms/releases/tag/v0.5.1"},{"type":"EVIDENCE","url":"https://github.com/mano257200/TSI-DPDP-CMS-Missing-Authentication/blob/main/README.md"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tsi-coop/tsi-dpdp-cms","events":[{"introduced":"c2c8732cf7abc8e093299fec015615bce6524043"},{"fixed":"18f35f04447872a3243b75b5a8aeaa1fd7239bef"}],"database_specific":{"extracted_events":[{"introduced":"0.1"},{"last_affected":"0.1"},{"introduced":"0.2"},{"last_affected":"0.2"},{"introduced":"0.3"},{"last_affected":"0.3"},{"introduced":"0.4"},{"last_affected":"0.4"},{"introduced":"0.5.0"},{"last_affected":"0.5.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["0.1","0.2","0.3","0.4","0.5.0","v0.5.0","v0.4.9","v0.4.8","v0.4.7","v0.4.6","v0.4.5","v0.4.4","v0.4.3","v0.4.2","v0.4.1","v0.4","v0.3","v0.2","v0.1"],"database_specific":{"vanir_signatures":[{"signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/AdminSetup.java"},"deprecated":false,"digest":{"line_hashes":["250472216722402734104061782355215519111","153515143207338275641410653895934773035","180614048942477380333626795275031769306","61778191575002692793210705736656462572","282269796761919970058660283271881534274","242639402441324601054616015366266054684","97956153476787394213694132196964340061","219101532630030447457509191542714540938","319332463195028898770369261630593076995","44557872028062078763778784495570543107","196218335496574331768596257037394660604","98398065208785670933147691124588261923","313679369130660551293440077035045957640","162124469803268952745358059571472066900","172468608257877802512527931760402118063","218350966992979505992395286075396186771","128003151044219072679611981512106381563","95260908930458339024692089559365831506","17717968067049525165987898077689208122","147986469541465501062514702993191623349","27440096732924321145083731353059044414","239802015861852721734850485192852252890","212845597264742464156419156857788404374","248718959639371394212277171601100420018","211506805339486380593034369393703143595","303986033984073245597258319862638396313","181295410957308451301983558760907521307","73850379356169208278266961016275074062","100389516977321388999224882846091797247"],"threshold":0.9},"id":"CVE-2026-84839-3edbe645","signature_type":"Line"},{"deprecated":false,"digest":{"function_hash":"170016251835083542850370707063958464017","length":2698},"id":"CVE-2026-84839-55829e31","signature_type":"Function","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/Operator.java","function":"handleLogin"}},{"digest":{"function_hash":"339345187394699435555257903700973392745","length":624},"id":"CVE-2026-84839-632a42f2","signature_type":"Function","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/AdminSetup.java","function":"performInitialSetup"},"deprecated":false},{"source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/framework/InputProcessor.java"},"deprecated":false,"digest":{"line_hashes":["168144796550234577620461396633821165010","190479784715125092852073431253829443147","97133016112726292342217523854869350936"],"threshold":0.9},"id":"CVE-2026-84839-71296fb7","signature_type":"Line","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/Operator.java","function":"handleLogout"},"deprecated":false,"digest":{"function_hash":"254499771655642101752609818917179779296","length":751},"id":"CVE-2026-84839-7bf6db81"},{"target":{"file":"src/org/tsicoop/dpdpcms/service/v1/AdminSetup.java","function":"post"},"deprecated":false,"digest":{"function_hash":"47764483691264100578833822551024191969","length":2071},"id":"CVE-2026-84839-957e81e4","signature_type":"Function","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef"},{"deprecated":false,"digest":{"line_hashes":["54105518578364645003510450566180077590","315215604280527446040488662872011241977"],"threshold":0.9},"id":"CVE-2026-84839-97c0235b","signature_type":"Line","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/util/Constants.java"}},{"digest":{"line_hashes":["81470657570310543048476049778456254968","167197765425960899165223372759656597541","19582413581543432790224381119387506264","146740561993377831685318827170744327560","76044978758252598220312339646365501598","191146923176190635191133456777986574041","70922012124940125287253867064884911925","203000558782833075064361349094631607427"],"threshold":0.9},"id":"CVE-2026-84839-a6bb2a79","signature_type":"Line","signature_version":"v1","source":"https://github.com/tsi-coop/tsi-dpdp-cms/commit/18f35f04447872a3243b75b5a8aeaa1fd7239bef","target":{"file":"src/org/tsicoop/dpdpcms/service/v1/Operator.java"},"deprecated":false}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-84839.json","vanir_signatures_modified":"2026-09-04T08:02:29Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P"}]}