Authenticated Remote Code Execution in openEQUELLA by OpenEQUELLA
CVE-2026-67615
8.7HIGH
What is CVE-2026-67615?
The openEQUELLA platform, prior to version 2026.1.0, harbors a significant vulnerability that permits authenticated users to execute arbitrary code. This is achieved through a flaw in the Java deserialization process associated with the HTTP invoker endpoint. By circumventing the class-name denylist via nested serialized payloads within a java.security.SignedObject, adversaries can trigger an ObjectInputStream that ignores the denylist protections. This ultimately leads to the deserialization of malicious code at a JNDI sink, allowing for potential code execution on the server.
Affected Version(s)
openEQUELLA 0 < 2026.1.0
