What is CVE-2026-15563?
CVE-2026-15563 is a flaw in EAP's IIOP where the NameService accepts bind operations without authentication. This allows an attacker to hijack JNDI lookups by binding them to a malicious ORB, enabling MITM or DoS attacks on subsequent invocations.
Azərbaycanca: CVE-2026-15563, EAP-in IIOP komponentində autentifikasiya olmadan bind əməliyyatlarını qəbul edən bir qüsurdur. Bu, təcavüzkara JNDI sorğularını ələ keçirərək zərərli ORB-yə yönləndirməyə və MITM və ya DoS hücumları həyata keçirməyə imkan verir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
In which component of EAP was the CVE-2026-15563 vulnerability discovered?
The CVE-2026-15563 vulnerability was discovered in the IIOP component of EAP.
What attacks can be carried out by an attacker exploiting CVE-2026-15563 by hijacking JNDI lookups?
An attacker exploiting CVE-2026-15563 can carry out MITM or DoS attacks by hijacking JNDI lookups to a malicious ORB.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.