What is CVE-2026-15554?
CVE-2026-15554 is a vulnerability in the Undertow AJP listener that honors forged 'ssl_cert' and 'is_ssl' attributes without requiring shared-secret authentication. This allows an unauthenticated attacker with direct TCP access to port 8009 to bypass CLIENT-CERT authentication by injecting a forged X.509 certificate. Affected servers must enable shared-secret authentication for the AJP listener.
Azərbaycanca: CVE-2026-15554, Undertow AJP listener komponentində autentifikasiya olmadan 'ssl_cert' və 'is_ssl' atributlarının saxtalaşdırılmasına imkan verən boşluqdur. Bu zəiflik, 8009 portuna birbaşa TCP girişi olan hücumçuya CLIENT-CERT autentifikasiyasını keçərək sistemə müdaxilə etməyə şərait yaradır. Təsirə məruz qalan serverlərdə AJP listener üçün paylaşılan sirr (shared secret) autentifikasiyası mütləq aktivləşdirilməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which port can be used to exploit CVE-2026-15554?
This vulnerability can be exploited if an attacker has direct TCP access to port 8009.
What mitigation is recommended for CVE-2026-15554?
Affected servers must enable shared-secret authentication for the AJP listener.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.