PT-2026-36315 · Apache+2 · Apache Mina+2

CVE-2026-42779

·

Published

2026-05-01

·

Updated

2026-07-04

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Apache MINA versions 2.1.0 through 2.1.11 Apache MINA versions 2.2.0 through 2.2.6
Description An insecure deserialization flaw exists in the Apache MINA network application framework. The resolveClass() function within AbstractIoBuffer contains a logic branch for static classes or primitive types that fails to validate the class against the classname allowlist. This bypass allows a remote attacker to execute arbitrary code on the server without authentication when the application calls the getObject() function of IoBuffer. This issue impacts the confidentiality, integrity, and availability of the protected information.
Recommendations Upgrade Apache MINA versions 2.1.0 through 2.1.11 to version 2.1.12. Upgrade Apache MINA versions 2.2.0 through 2.2.6 to version 2.2.7.

Exploit

Fix

LPE

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-06348
CLEANSTART-2026-DD05788
CLEANSTART-2026-LE11246
CLEANSTART-2026-LO22603
CLEANSTART-2026-RN56220
CVE-2026-42779
GHSA-VF5J-865M-MQ7C
OESA-2026-2241
OESA-2026-2242
OESA-2026-2243
OESA-2026-2244
OESA-2026-2245
USN-8465-1

Affected Products

Apache Mina
Linuxmint
Ubuntu