Deserialization Vulnerability in Apache Axis2/Java Affecting Apache Software Foundation
CVE-2026-66713
Currently unrated
What is CVE-2026-66713?
A vulnerability exists in the Tribes-based clustering component of Apache Axis2/Java, specifically in versions prior to 2.0.1, which allows an unauthenticated remote attacker with access to the clustering port to exploit deserialization of untrusted data. By sending a crafted serialized Java object through the cluster channel, an attacker can trigger arbitrary code execution when the object is deserialized. To mitigate this risk, users are strongly advised to update to version 2.0.1, which resolves this vulnerability by removing the Tribes clustering feature altogether.
Affected Version(s)
Apache Axis2/Java 0 <= 2.0.0