Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Workaround
Deployments that can't upgrade immediately should firewall or VPN the /invoker/* endpoints and restrict them to only those who genuinely need access.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 22 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint at /invoker/*. Attackers can bypass the class-name denylist enforced by PluginAwareObjectInputStream by nesting a serialized payload inside a java.security.SignedObject, causing the inner stream to be deserialized by a separate ObjectInputStream that does not apply the denylist, ultimately reaching a JNDI sink and enabling code execution. | |
| Title | openEQUELLA < 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Invoker | |
| Weaknesses | CWE-184 CWE-502 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-22T20:30:55.804Z
Reserved: 2026-07-29T21:07:39.203Z
Link: CVE-2026-67615
No data.
Status : Received
Published: 2026-09-22T21:17:31.100
Modified: 2026-09-22T21:17:31.100
Link: CVE-2026-67615
No data.
OpenCVE Enrichment
Updated: 2026-09-22T21:30:20Z