{"id":"CVE-2026-67615","summary":"openEQUELLA \u003c 2026.1.0 Authenticated RCE via Java Deserialization in HTTP Invoker","details":"openEQUELLA before 2026.1.0 contains an authenticated remote code execution vulnerability that allows any authenticated non-guest user to execute arbitrary code by exploiting Java deserialization in the HTTP invoker endpoint at /invoker/*. Attackers can bypass the class-name denylist enforced by PluginAwareObjectInputStream by nesting a serialized payload inside a java.security.SignedObject, causing the inner stream to be deserialized by a separate ObjectInputStream that does not apply the denylist, ultimately reaching a JNDI sink and enabling code execution.","modified":"2026-09-26T03:30:17.239379470Z","published":"2026-09-22T20:30:55.804Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67615.json","cna_assigner":"VulnCheck","cwe_ids":["CWE-184","CWE-502"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/67xxx/CVE-2026-67615.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-67615"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/openequella-authenticated-rce-via-java-deserialization-in-http-invoker"},{"type":"FIX","url":"https://github.com/openequella/openEQUELLA/releases/tag/2026.1.0"},{"type":"PACKAGE","url":"https://github.com/openequella/openEQUELLA"},{"type":"EVIDENCE","url":"https://blog.evan.lat/posts/openeq"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openequella/openequella","events":[{"introduced":"0"},{"fixed":"25e9002452cf7d18ec96500cdfdb433126e70cac"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2026.1.0"}],"source":["AFFECTED_FIELD","DESCRIPTION","REFERENCES"]}}],"versions":["2025.2.0","2025.1.0","2024.2.0","2024.1.0","2023.2.0","2023.1.0","2022.2.0","2022.1.0","2021.2.3","2021.2.2","2021.2.1","2020.2.0","2021.1.2","2021.2.0","2021.1.1","2021.1.0","2020.1.6","2020.1.5","2020.1.4","2020.1.3","2020.1.2","2020.1.1","2019.2.1","2020.1.0","2019.2.0","2019.2-RC","start-2019.2","pre-mega-format","2018.2-Stable","2018.2-RC1","6.6-Stable","6.6-RC2","6.6-RC1","6.5-Stable","6.5-Beta","6.5-Alpha","6.4-Beta","6.4-Alpha"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-67615.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}