CVE-2026-33046 is a high-severity vulnerability (CVSS 8.8) affecting Indico event management systems prior to version 3.3.12. This flaw allows authenticated attackers with low privileges to execute arbitrary code or read local files on the server by exploiting weaknesses in TeXLive and obscure LaTeX syntax, provided server-side LaTeX rendering is enabled. The attack vector is network-based, requires low complexity, and results in high impact on confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code available, it is strongly recommended to update to Indico 3.3.12 or disable LaTeX rendering as a workaround.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.3.12CPE matchmatch criteria | cpe:2.3:a:cern:indico:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.