PT-2026-95961 · Unknown · Openequella
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
openEQUELLA versions prior to 2026.1.0
Description
Remote code execution is possible during FreeMarker template compilation because of an unsandboxed
TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions via collection summaries, dashboard portlets, or MIME templates. This allows the instantiation of dangerous classes, such as freemarker.template.utility.Execute, to invoke Runtime.exec() for arbitrary command execution.Recommendations
Update to version 2026.1.0.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openequella