CERN's vulnerability disclosures center on a narrow portfolio of scientific and research-infrastructure tools, including the Indico event-management platform, Rucio data-management system, and ROOT data-analysis framework, which serve specialized but globally distributed communities of researchers and high-energy physics collaborators. The recurring vulnerability classes span application-layer input handling and access control: cross-site scripting, OS command injection, SQL injection, and authorization-bypass conditions reflect the complexity of web interfaces and data-access layers that must integrate with large-scale distributed systems. The profile is characteristic of research software where security maturity and attack-surface awareness evolve as tools transition from internal use to broader adoption; defenders relying on these platforms should prioritize updates affecting authentication, command execution, and query-processing code paths. Current exploitation activity, severity distributions, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Cern over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-29080HIGH A SQL injection vulnerability in `FilterEngine.create_sqla_query()` allows any authenticated Rucio user to execute arbitrary SQL against the backend database through the DID search | May 6, 2026 | 8.8 | 31 | NO | NO |
CVE-2026-29090HIGH ### Summary
A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgres_query()`. This allo | May 6, 2026 | 8.8 | 29 | NO | NO |
CVE-2026-33046HIGH Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.12, due to vulnerabilities in TeXLive and | Mar 23, 2026 | 8.8 | 29 | NO | NO |
CVE-2017-1000203HIGH ROOT version 6.9.03 and below is vulnerable to an authenticated shell metacharacter injection in the rootd daemon resulting in remote code execution | Nov 17, 2017 | 8.8 | 28 | NO | NO |
CVE-2026-28352MEDIUM Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. In versions prior to 3.3.11, the API endpoint used to manage event | Feb 27, 2026 | 6.5 | 23 | NO | NO |
CVE-2026-25136MEDIUM Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. A reflected Cross-site Scrip | Feb 25, 2026 | 6.1 | 23 | NO | NO |
CVE-2021-30185HIGH CERN Indico before 2.3.4 can use an attacker-supplied Host header in a password reset link. | Apr 7, 2021 | 7.5 | 22 | NO | NO |
CVE-2026-25733MEDIUM Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38 | Feb 25, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-25736MEDIUM Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38 | Feb 25, 2026 | 4.8 | 20 | NO | NO |
CVE-2026-25735MEDIUM Rucio is a software framework that provides functionality to organize, manage, and access large volumes of scientific data using customizable policies. Versions prior to 35.8.3, 38 | Feb 25, 2026 | 4.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Cern.
Media articles that mention a CVE ID that affects a product developed by Cern — matched by CVE ID, not by vendor name.