PT-2026-22063 · Unknown+3 · Mchange-Commons-Java+3

·

CVE-2026-27830

·

Published

2026-02-16

·

Updated

2026-08-18

CVSS v4.0

8.9

High

VectorAV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions c3p0 versions prior to 0.12.0
Description A flaw in the JDBC connection pooling library allows a remote attacker to achieve arbitrary code execution on the application's CLASSPATH. The issue exists because several ConnectionPoolDataSource implementations use a property called userOverridesAsString that was maintained as a hex-encoded Java serialized object. An attacker can manipulate this property using maliciously crafted Java-serialized objects or javax.naming.Reference instances to trigger deserialization. This risk is increased by a dependency on mchange-commons-java, which provides ungated support for remote factoryClassLocation values. By combining these, an attacker can force the application to download and execute malicious code from a remote location. JNDI (Java Naming and Directory Interface) is a Java API that allows applications to discover and look up data and objects via a name.
Recommendations Update c3p0 to version 0.12.0 or above.

Exploit

Fix

Code Injection

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-10880
CVE-2026-27830
GHSA-5476-XC4J-RQCV
OESA-2026-1691
RHSA-2026:18054
RHSA-2026:18055
RHSA-2026:28385
SUSE-SU-2026:0855-1
SUSE-SU-2026:1035-1
USN-8642-1

Affected Products

Linuxmint
Ubuntu
C3P0
Mchange-Commons-Java