CVE-2026-11815

Severity CVSS v4.0:
MEDIUM
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
10/06/2026
Last modified:
10/06/2026

Description

An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken security expectations or remote code execution.