Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-66909

Gravedad CVSS v3.1:
CRÍTICA
Tipo:
CWE-502 Deserialización de datos no confiables
Fecha de publicación:
06/08/2026
Última modificación:
06/08/2026

Descripción

*** Pendiente de traducción *** Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* 3.6.12 (excluyendo)
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* 4.0.0 (incluyendo) 4.1.8 (excluyendo)
cpe:2.3:a:apache:cxf:*:*:*:*:*:*:*:* 4.2.0 (incluyendo) 4.2.3 (excluyendo)


Referencias a soluciones, herramientas e información