CVE-2026-11815
Severity CVSS v4.0:
MEDIUM
Type:
CWE-502
Deserialization of Untrusted Dat
Publication date:
10/06/2026
Last modified:
10/06/2026
Description
An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution.
Impact
Base Score 4.0
5.30
Severity 4.0
MEDIUM



