# Security Release for issue 15035

**URL:** https://discuss.tryton.org/t/security-release-for-issue-15035/9412
**Category:** News
**Created:** [October 5, 2026, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-15035/9412 "2026-10-05T06:00:21Z")
**Posts on this page:** 1
**Page:** 1

<div class="post-metadata">

### Author: ![ced](https://discuss-cdn.tryton.org/user_avatar/discuss.tryton.org/ced/32/1237_2.png) [@ced](https://discuss.tryton.org/u/ced)
#### Post date: [October 5, 2026, 6:00am UTC](https://discuss.tryton.org/t/security-release-for-issue-15035/9412/1 "2026-10-05T06:00:21Z")

</div>

[lizparadox\_](https://foss.heptapod.net/paradox0909) has discovered that [the report name can be used to execute commands on the server](https://bugs.tryton.org/15035).

## Impact

[CVSS v3.0 Base Score: 6.8](https://www.first.org/cvss/calculator/3-0#CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H)

- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: High
- User Interaction: Required
- Scope: Unchanged
- Confidentiality: High
- Integrity: High
- Availability: High

## Workaround

There is no workaround.

## Resolution

All affected users should upgrade `trytond` to the latest version.

Affected versions per series:

- `trytond`:
  - 8.0: \<= 8.0.10
  - 7.8: \<= 7.8.16

Not affected versions per series:

- `trytond`:
  - 8.0: \>= 8.0.11
  - 7.8: \>= 7.8.17

## Reference

- [https://bugs.tryton.org/15035](https://bugs.tryton.org/15035)

## Concerns?

Any security concerns should be reported on the bug-tracker at [https://bugs.tryton.org/](https://bugs.tryton.org/) with the confidential checkbox checked.
