{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aapachecommons_beanutils/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apache:commons_beanutils:*:*:*:*:*:*:*:*","cpe:2.3:a:apache:commons_beanutils:2.0.0:milestone1:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2025-48734"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Commons Beanutils"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Apache"],"content_html":"\u003cp\u003eCVE-2025-48734 affects Apache Commons BeanUtils versions prior to 1.11.0 (and 2.0.0-M2), allowing unauthenticated attackers to access the 'declaringClass' property of Java enums. By exploiting PropertyUtilsBean to access nested properties like 'enum.declaringClass.classLoader', an attacker can leak the application's ClassLoader. This vulnerability does not provide RCE directly; however, it functions as a critical reconnaissance pivot for identifying vulnerable gadget libraries (e.g., Commons Collections 3.x) within the classpath. When an application also exposes an unsafe Java deserialization endpoint, this information leak allows an attacker to reliably trigger an RCE chain. The vulnerability is highly relevant to enterprise environments utilizing legacy Java applications or shared middleware.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies an endpoint accepting property path inputs processed by PropertyUtilsBean (e.g., /api/property?path=...).\u003c/li\u003e\n\u003cli\u003eAttacker injects a malicious property path targeting 'status.declaringClass' to verify access to the enum internal class.\u003c/li\u003e\n\u003cli\u003eAttacker pivots to 'status.declaringClass.classLoader' to obtain a reference to the application ClassLoader.\u003c/li\u003e\n\u003cli\u003eAttacker iterates through the ClassLoader URL array to enumerate all loaded JAR files, identifying presence of vulnerable gadget libraries like Commons Collections 3.2.2.\u003c/li\u003e\n\u003cli\u003eAttacker fuzzes application endpoints (e.g., /api/data/import) to identify a target supporting Java deserialization by sending the '0xACED0005' magic header.\u003c/li\u003e\n\u003cli\u003eAttacker utilizes ysoserial to generate a gadget-based payload (e.g., CommonsCollections6) specific to the identified environment.\u003c/li\u003e\n\u003cli\u003eAttacker delivers the serialized payload via HTTP POST to the identified deserialization endpoint.\u003c/li\u003e\n\u003cli\u003eRemote code execution occurs during the object reconstruction process, executing the attacker-provided command on the target host.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to full remote code execution, granting the attacker arbitrary command execution capabilities with the privileges of the web application service account. This allows for total system compromise, data exfiltration, or lateral movement within the network. The vulnerability impacts any application using affected versions of Apache Commons BeanUtils that exposes property path manipulation combined with unsafe deserialization.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Apache Commons BeanUtils to version 1.11.0 or 2.0.0-M2 immediately to patch CVE-2025-48734.\u003c/li\u003e\n\u003cli\u003eImplement strict Java ObjectInputFilter controls on all deserialization endpoints to permit only necessary classes.\u003c/li\u003e\n\u003cli\u003eAudit application code for usage of PropertyUtilsBean where the 'path' parameter is derived from untrusted user input.\u003c/li\u003e\n\u003cli\u003eUse the CVE-2025-48734 remediation to prevent classpath enumeration reconnaissance, breaking the RCE chain at the initial discovery phase.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-25T22:00:24Z","date_published":"2026-08-25T22:00:24Z","id":"https://feed.craftedsignal.io/briefs/2026-08-beanutils-rce/","summary":"CVE-2025-48734 enables attackers to enumerate the Java classpath and ClassLoader via property injection, facilitating RCE when chained with unsafe deserialization endpoints.","title":"Apache Commons BeanUtils Information Leak and RCE Chain","url":"https://feed.craftedsignal.io/briefs/2026-08-beanutils-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:apache:commons_beanutils:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}