Server-Side Request Forgery and Local File Inclusion in Apache MyFace Core
CVE-2026-68536

9.8CRITICAL

Key Information:

Vendor

Apache

Vendor
CVE Published:
16 September 2026

What is CVE-2026-68536?

A vulnerability in Apache MyFace Core allows for Server-Side Request Forgery and Local File Inclusion, potentially compromising sensitive information and system integrity. This vulnerability affects older and unsupported versions of the software. To mitigate these risks, it is crucial for users to upgrade to secured versions such as 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which contain the necessary patches.

Affected Version(s)

Apache MyFaces 2.2.0-beta <= 2.2.15

Apache MyFaces 2.3.0

Apache MyFaces 2.3-next-M1 < 2.3-next-M9

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.