CVE -2026-19929 exposes a serious issue in the way OpenBoxes handles Zebra templates. The vulnerability allows a remote attacker to interfere with the tag generation process and exploit the template mechanism on the server.

The vulnerability affects OpenBoxes versions up to 0.9.6 and was reported on August 15, 2026. According to the NVD entry, the issue is related to incomplete neutralization of special elements in a template mechanism, while the public report describes an available exploit.
See also: Thymeleaf: Critical sandbox bypass vulnerability fixed
How OpenBoxes' Zebra standards are affected
OpenBoxes is an inventory and supply chain management platform, also used in healthcare organizations. CVE-2026-19929 is located in the buildZebraTemplate of DocumentController.groovy, which is involved in processing documents used for Zebra tags.
The problem is not just about an incorrect label appearance. The older implementation relied on a mechanism that could evaluate expressions as Groovy code. A specially crafted template could thus lead to the execution of commands on the server, with consequences that depend on the privileges of the service and the infrastructure of each installation.
NVD says the attack can be launched remotely and gives the vulnerability a CVSS-BT 2.1 rating with low severity because it already requires authenticated access. The original CVE Alert listing shows a different rating of 6.3, which suggests that organizations shouldn't rely on a single numerical indicator alone.
The fix for Zebra templates
The official change replaces GroovyPagesTemplateEngine with a service that only allows access to JavaBean properties. This way, a template can read allowed values, such as the product code, but cannot execute methods, arithmetic operations, or arbitrary expressions.
The new implementation also checks binding names, rejects GSP syntax, and blocks properties that could lead to access to metadata or class loading mechanisms. The relevant GitHub commit describes the changes and tests added to make Zebra templates more secure.
OpenBoxes 0.9.8 includes the fix, while the release notes explicitly state that it addresses a Server-Side Template Injection vulnerability that could lead to RCE. For those who cannot upgrade immediately, temporarily reducing the exposure of document management functions and strict access logging are mitigation measures, not a permanent solution.
Requiring authenticated access does not eliminate risk. In a deployment where multiple users can upload or modify documents, template creation permissions may be broader than necessary. Service isolation and limited administrative access reduce the potential for abuse, but they are not a substitute for updating.
The 0.9.8 release notes mention, along with the Zebra template issue, fixes for SSRF in document uploads and privilege escalation. The vulnerabilities have different attack vectors, but their coexistence reinforces the need for overall installation control rather than individual file changes.

See also: SGLang: Vulnerability allows RCE via malicious GGUF files
What should administrators do?
Administrators should document installations running version 0.9.6 and plan to upgrade to 0.9.8 or later. They should also review documents used as Zebra templates, look for unusual changes, and review the accounts that have permission to create or edit them.
The SecNews technical team recommends treating CVE-2026-19929 as an implementation vulnerability rather than a simple formatting issue. In environments where OpenBoxes has access to databases, storage, or internal services, a successful exploit could significantly expand the impact of an initial account.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: CVE-2026-18855: Critical vulnerability in WordPress Link Library
After upgrading, it is useful to check the logs for requests to the buildZebraTemplate, renderZebraTemplate , and exportZebraTemplate. Unusual activity, new prints without a corresponding operational action, or changes to template files can provide indications of previous abuse and lead to targeted auditing.
The upgrade should be combined with a review of user rights, protection of administrative paths, and separation of OpenBoxes from unnecessary internal services. This limits the potential for an attack to continue, even if an account has already been compromised.
The security of templates ultimately depends on whether the system treats them as data or code. OpenBoxes' move to restricted property resolution closes this dangerous path, but installing the patched version remains necessary for any exposed environment.
