What is CVE-2026-15555?
A flaw in JBoss Marshalling allows the Infinispan session replication path to deserialize data via JBoss Marshalling River unmarshaller without class filtering. This could enable Remote Code Execution (RCE) through deserialization gadget chains on every cluster node without authentication. Immediate patching and network access restrictions are strongly recommended.
Azərbaycanca: JBoss Marshalling-də aşkarlanan bu boşluq Infinispan sessiya replikasiyası zamanı xüsusi sinif filtrləməsi olmadan deserializasiya prosesini həyata keçirir. Bu, autentifikasiya olunmamış uzaqdan kod icrasına (Remote Code Execution) səbəb ola bilər. Təşkilatlar dərhal təhlükəsizlik yeniləmələrini tətbiq etməli və şəbəkə səviyyəsində giriş nəzarətlərini gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-502
FAQ1
In which technology was CVE-2026-15555 discovered and what is the primary risk?
The flaw was discovered in JBoss Marshalling during Infinispan session replication. Because deserialization occurs without class filtering, it could lead to unauthenticated Remote Code Execution (RCE).
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.