PT-2026-65496 · Apache · Apache Tomcat+1

·

CVE-2026-66713

·

Published

2026-07-28

·

Updated

2026-08-05

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Apache Axis2/Java versions prior to 2.0.1
Description An issue exists in the Tribes-based clustering component when running on Apache Tomcat. When Tribes clustering is enabled, an unauthenticated remote attacker with network access to the clustering port can execute arbitrary code. This is achieved by sending a crafted serialized Java object to the cluster channel, which is then deserialized in the messageReceived() function of org.apache.axis2.clustering.tribes.Axis2ChannelListener. Deserialization is the process of converting a stream of bytes back into an object in memory.
Recommendations Upgrade to version 2.0.1. As a temporary workaround, ensure that Tribes clustering remains disabled.

Exploit

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-66713

Affected Products

Apache Axis2
Apache Tomcat