What is CVE-2026-46581?
In Eclipse Mojarra versions 2.3 and later, insufficient sanitization in `DefaultFaceletFactory` URL handling allows attackers to include remote Facelets. These files are processed with the target application's privileges, potentially leading to remote code execution. Immediate patching and restricting access to external resources are strongly recommended.
Azərbaycanca: Eclipse Mojarra 2.3 və sonrakı versiyalarında `DefaultFaceletFactory` URL emalında sanitizasiya çatışmazlığı aşkarlanıb. Bu zəiflik uzaqdan Facelet faylının daxil edilməsinə imkan verir, hədəf sistemin imtiyazları ilə işlənə bilər. Təcili olaraq müvafiq təhlükəsizlik yeniləmələri tətbiq edilməli və xarici resurslara giriş məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-94
FAQ1
Which component is affected by CVE-2026-46581 and what is the associated risk?
The vulnerability lies in the insufficient sanitization in `DefaultFaceletFactory` URL handling in Eclipse Mojarra versions 2.3 and later. Attackers can include remote Facelets, which are processed with the target application's privileges, potentially leading to remote code execution.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.