{"id":"CVE-2026-75987","summary":"SPLWare esProc SocketData.java ObjectInputStream.readUnshared deserialization","details":"A vulnerability was found in SPLWare esProc up to 20260507. This affects the function ObjectInputStream.readUnshared of the file src/main/java/com/scudata/parallel/SocketData.java. Performing a manipulation results in deserialization. Remote exploitation of the attack is possible.","modified":"2026-08-23T03:42:27.331084853Z","published":"2026-08-19T01:45:09.722Z","database_specific":{"cna_assigner":"VulDB","cwe_ids":["CWE-20","CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75987.json"},"references":[{"type":"WEB","url":"https://github.com/SPLWare/esProc/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75987.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75987"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-75987"},{"type":"ADVISORY","url":"https://vuldb.com/submit/877849"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/391906"},{"type":"REPORT","url":"https://github.com/SPLWare/esProc/issues/67"},{"type":"REPORT","url":"https://vuldb.com/vuln/391906/cti"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/splware/esproc","events":[{"introduced":"207fe4cefba4779a9ae41843f162796a957a4ccc"},{"last_affected":"207fe4cefba4779a9ae41843f162796a957a4ccc"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"20260507"},{"last_affected":"20260507"}]}}],"versions":["20260507","V20260507"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75987.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}