PT-2026-78259 · Splware · Esproc

·

CVE-2026-75987

·

Published

2026-08-19

·

Updated

2026-08-21

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SPLWare esProc versions prior to 20260507
Description An issue exists where performing a manipulation leads to deserialization, which is the process of converting a byte stream back into an object. This occurs within the ObjectInputStream.readUnshared() function located in the src/main/java/com/scudata/parallel/SocketData.java file, allowing for remote exploitation.
Recommendations Update to a version released after 20260507. As a temporary workaround, restrict access to the ObjectInputStream.readUnshared() function to minimize the risk of exploitation.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-75987

Affected Products

Esproc