CVE-2026-94109
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
20/09/2026
Last modified:
24/09/2026
Description
openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by storing a malicious FreeMarker payload through a POST request to the RemotePortletService invoker endpoint. The markup field from stored portlet configuration is passed directly to custFactory.createResult() without a TemplateClassResolver restriction or FreeMarker sandboxing in BasicConfiguration, leaving built-ins such as ?new and freemarker.template.utility.Execute available, causing the payload to execute in the application server process context when any user renders a dashboard containing the affected portlet.
Impact
Base Score 4.0
8.60
Severity 4.0
HIGH
Base Score 3.x
8.00
Severity 3.x
HIGH


