What is CVE-2026-66713?
This CVE represents a deserialization of untrusted data vulnerability in Apache Axis2/Java up to version 2.0.0, occurring only when Tribes-based clustering is enabled (off by default). An unauthenticated remote attacker with network access can exploit this on the affected Apache Tomcat server. To mitigate, disable the Tribes clustering feature or update to the latest version.
Azərbaycanca: Bu CVE, Apache Axis2/Java versiya 2.0.0-dək olan proqramda, yalnız Tribes əsaslı clustering aktiv olduqda (default olaraq söndür) baş verən etibarsız məlumatın deserializasiyası zəifliyini təmsil edir. Şəbəkəyə çıxışı olan autentifikasiya olunmamış uzaqdan hücumçu bu zəiflik vasitəsilə təsirə məruz qalmış Apache Tomcat serverinə qarşı hücum həyata keçirə bilər. Təsirə məruz qalmamaq üçün Tribes clustering funksiyasını deaktiv etmək və ya proqramı ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502; shared vendor: Apache
FAQ2
What condition is required to be affected by CVE-2026-66713 in Apache Axis2/Java?
This vulnerability occurs only when the Tribes-based clustering feature is enabled (off by default).
What measures should be taken to protect against CVE-2026-66713?
To mitigate the risk, it is recommended to disable the Tribes clustering feature or update to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.