{"id":"UBUNTU-CVE-2022-26661","details":"An XXE issue was discovered in Tryton Application Platform (Server) 5.x through 5.0.45, 6.x through 6.0.15, and 6.1.x and 6.2.x through 6.2.5, and Tryton Application Platform (Command Line Client (proteus)) 5.x through 5.0.11, 6.x through 6.0.4, and 6.1.x and 6.2.x through 6.2.1. An authenticated user can make the server parse a crafted XML SEPA file to access arbitrary files on the system.","modified":"2026-05-20T16:06:42.576801902Z","published":"2022-03-10T17:47:00Z","upstream":["CVE-2022-26661"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-26661"},{"type":"REPORT","url":"https://bugs.tryton.org/issue11219"},{"type":"REPORT","url":"https://discuss.tryton.org/t/security-release-for-issue11219-and-issue11244/5059"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2022-26661"}],"affected":[{"package":{"name":"tryton-proteus","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/tryton-proteus?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.6.1-1","3.8.0-1","3.8.1-1"],"ecosystem_specific":{"binaries":[{"binary_version":"3.8.1-1","binary_name":"tryton-proteus"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:16.04:LTS","purl":"pkg:deb/ubuntu/tryton-server?arch=source&distro=xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["3.6.2-1","3.6.3-2","3.6.3-3","3.8.0-1","3.8.1-1","3.8.2-1","3.8.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-server","binary_version":"3.8.3-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-proteus","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/tryton-proteus?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.4.0-4","4.6.0-1","4.6.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-proteus","binary_version":"4.6.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/tryton-server?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["4.4.3-3","4.6.0-1","4.6.1-1","4.6.2-1","4.6.3-2"],"ecosystem_specific":{"binaries":[{"binary_version":"4.6.3-2","binary_name":"tryton-server"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-proteus","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/tryton-proteus?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.3-2","5.0.7-1"],"ecosystem_specific":{"binaries":[{"binary_version":"5.0.7-1","binary_name":"tryton-proteus"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/tryton-server?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.10-1","5.0.14-2","5.0.16-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-server","binary_version":"5.0.16-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-proteus","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/tryton-proteus?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.8-1","6.0.3-2"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-proteus","binary_version":"6.0.3-2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/tryton-server?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["5.0.33-2","6.0.9-3","6.0.12-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-server","binary_version":"6.0.12-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-proteus","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/tryton-proteus?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.0.8-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-proteus","binary_version":"6.0.8-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/tryton-server?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.0.34-1","6.0.36-1","6.0.39-1"],"ecosystem_specific":{"binaries":[{"binary_version":"6.0.39-1","binary_name":"tryton-server"},{"binary_name":"tryton-server-all-in-one","binary_version":"6.0.39-1"},{"binary_name":"tryton-server-nginx","binary_version":"6.0.39-1"},{"binary_name":"tryton-server-postgresql","binary_version":"6.0.39-1"},{"binary_version":"6.0.39-1","binary_name":"tryton-server-uwsgi"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-proteus","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/tryton-proteus?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.0.1-3"],"ecosystem_specific":{"binaries":[{"binary_version":"7.0.1-3","binary_name":"tryton-proteus"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/tryton-server?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.0.24-1","7.0.30-1"],"ecosystem_specific":{"binaries":[{"binary_version":"7.0.30-1","binary_name":"tryton-server"},{"binary_name":"tryton-server-all-in-one","binary_version":"7.0.30-1"},{"binary_name":"tryton-server-nginx","binary_version":"7.0.30-1"},{"binary_version":"7.0.30-1","binary_name":"tryton-server-postgresql"},{"binary_name":"tryton-server-uwsgi","binary_version":"7.0.30-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-proteus","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/tryton-proteus?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.0.1-3","7.0.2-1","7.0.3-1"],"ecosystem_specific":{"binaries":[{"binary_name":"tryton-proteus","binary_version":"7.0.3-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}},{"package":{"name":"tryton-server","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/tryton-server?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["7.0.30-1","7.0.38-1","7.0.40-1","7.0.43-1"],"ecosystem_specific":{"binaries":[{"binary_version":"7.0.43-1","binary_name":"tryton-server"},{"binary_name":"tryton-server-all-in-one","binary_version":"7.0.43-1"},{"binary_name":"tryton-server-nginx","binary_version":"7.0.43-1"},{"binary_version":"7.0.43-1","binary_name":"tryton-server-postgresql"},{"binary_version":"7.0.43-1","binary_name":"tryton-server-uwsgi"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2022/UBUNTU-CVE-2022-26661.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}