Deserialization Vulnerability in SPLWare esProc Affected Product
CVE-2026-75987

6.9MEDIUM

Key Information:

Vendor

Splware

Status
Vendor
CVE Published:
19 August 2026

What is CVE-2026-75987?

A deserialization vulnerability has been identified in SPLWare esProc, specifically within the ObjectInputStream.readUnshared function of the SocketData.java file. This flaw permits remote attackers to manipulate the deserialization process, potentially leading to unauthorized access or exploitation of the system. The vulnerability affects all versions of esProc up to 20260507, allowing attackers to execute malicious code remotely if exploited successfully.

Affected Version(s)

esProc 20260507

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ana10gy (VulDB User)
.