What is CVE-2026-66909?
CVE-2026-66909 affects Apache CXF where the JMS transport deserializes inbound JMS ObjectMessage bodies using native Java deserialization without type restrictions. This allows attackers who can place messages on the service's JMS destination to send malicious serialized objects, potentially causing denial of service or remote code execution. Affected users should apply type filtering on the JMS transport and restrict access to JMS destinations.
Azərbaycanca: CVE-2026-66909 Apache CXF-in JMS transport funksiyası daxil olan ObjectMessage mesajlarını heç bir tip məhdudiyyəti olmadan native Java deserialization ilə emal edir. Bu, xidmətin JMS təyinat nöqtəsinə mesaj yerləşdirə bilən hər hansı təcavüzkarın zərərli seriallaşdırılmış obyekt göndərərək denial of service (DoS) yaratmasına imkan verir. Təsirə məruz qalan Apache CXF istifadəçiləri JMS transport konfiqurasiyasında type filtering tətbiq etməli və giriş nəzarətini gücləndirməlidir.
Related CVEs
link basis: same weakness class CWE-502; shared vendor: Apache
FAQ2
Which function of Apache CXF does CVE-2026-66909 affect?
This vulnerability affects the JMS transport function of Apache CXF, where inbound ObjectMessage bodies are processed using native Java deserialization without type restrictions.
What outcome can an attacker exploiting CVE-2026-66909 cause?
An attacker who can place messages on the service's JMS destination can cause a denial of service (DoS) by sending a malicious serialized object.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.