PT-2026-97046 · Unknown · Openequella

·

CVE-2026-67615

·

Published

2026-09-22

·

Updated

2026-09-23

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions openEQUELLA versions prior to 2026.1.0
Description An authenticated non-guest user can execute arbitrary code via Java deserialization at the '/invoker/*' HTTP invoker endpoint. The issue occurs because the class-name denylist enforced by PluginAwareObjectInputStream can be bypassed by nesting a serialized payload within a java.security.SignedObject. This causes the inner stream to be processed by a separate ObjectInputStream that lacks the denylist, eventually reaching a JNDI sink. JNDI (Java Naming and Directory Interface) is a Java API that allows applications to discover and look up data and objects.
Recommendations Update to version 2026.1.0.

Exploit

Fix

RCE

Incomplete List of Disallowed Inputs

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-67615

Affected Products

Openequella