What is CVE-2026-15560?
CVE-2026-15560 is a vulnerability in the openjdk-orb's JDKBridge when EAP runs with -secmgr, where attacker-supplied CDR codebase URLs are honored during object unmarshalling on port :3528. It allows an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors execute.
Azərbaycanca: CVE-2026-15560, JBoss EAP -secmgr rejimində işləyərkən openjdk-orb-in JDKBridge komponentindəki zəiflikdir. Bu, autentifikasiya olunmamış hücumçuya :3528 portu üzərindən uzaq URL-dən ixtiyari siniflər yükləməyə imkan verir, EJB təhlükəsizlik interceptorları işə düşməzdən əvvəl server JVM-də kod icrasına səbəb ola bilər. Təsirə məruz qalan sistemlərdə -secmgr parametrinin istifadəsini nəzərdən keçirmək və müvafiq təhlükəsizlik yeniləmələrini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Under what condition is CVE-2026-15560 exploitable in JBoss EAP?
The vulnerability is exploitable only when JBoss EAP runs with the `-secmgr` flag in the openjdk-orb's JDKBridge component.
What can an unauthenticated attacker achieve by exploiting CVE-2026-15560?
An attacker can load and instantiate arbitrary classes from a remote URL via port :3528, leading to code execution in the server JVM before EJB security interceptors execute.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.