PT-2026-97046 · Unknown · Openequella
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
openEQUELLA versions prior to 2026.1.0
Description
An authenticated non-guest user can execute arbitrary code via Java deserialization at the '/invoker/*' HTTP invoker endpoint. The issue occurs because the class-name denylist enforced by
PluginAwareObjectInputStream can be bypassed by nesting a serialized payload within a java.security.SignedObject. This causes the inner stream to be processed by a separate ObjectInputStream that lacks the denylist, eventually reaching a JNDI sink. JNDI (Java Naming and Directory Interface) is a Java API that allows applications to discover and look up data and objects.Recommendations
Update to version 2026.1.0.
Exploit
Fix
RCE
Incomplete List of Disallowed Inputs
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openequella