Primefaces · Primereact · CVE-2026-15538
**Name of the Vulnerable Software and Affected Versions**
primefaces primereact versions prior to 10.9.9
**Description**
A weakness in the API component allows remote attackers to cause improperly controlled modification of object prototype attributes. This occurs through the manipulation of the `Field` argument within the `ObjectUtils.mutateFieldData()` function. This issue specifically affects products that are no longer supported by the maintainer.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.