Deserialization Vulnerability in Apache Axis2/Java Affecting Apache Software Foundation
CVE-2026-66713

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 July 2026

What is CVE-2026-66713?

A vulnerability exists in the Tribes-based clustering component of Apache Axis2/Java, specifically in versions prior to 2.0.1, which allows an unauthenticated remote attacker with access to the clustering port to exploit deserialization of untrusted data. By sending a crafted serialized Java object through the cluster channel, an attacker can trigger arbitrary code execution when the object is deserialized. To mitigate this risk, users are strongly advised to update to version 2.0.1, which resolves this vulnerability by removing the Tribes clustering feature altogether.

Affected Version(s)

Apache Axis2/Java 0 <= 2.0.0

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

liuhuajin of Huawei
.