{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aflocifloci1.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:floci:floci:1.1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-108598"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Floci (1.1.0-2.1.9)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Floci"],"content_html":"\u003cp\u003eFloci versions 1.1.0 through 2.1.9 are susceptible to a critical remote code execution vulnerability (CVE-2026-108598) located within the VtlTemplateEngine component. The vulnerability arises from unrestricted processing of Velocity mapping templates used in API integrations. An unauthenticated attacker can exploit this by creating a REST API endpoint configured with a MOCK integration. By injecting malicious Velocity syntax that utilizes '$util' reflection, the attacker can access dangerous Java classes such as 'Runtime' or 'ProcessBuilder'. This allows the execution of arbitrary OS commands with the privileges of the Floci Java Virtual Machine process. This flaw poses a high risk to organizational infrastructure, as it provides a trivial vector for initial access and full system compromise without requiring authentication.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker identifies an internet-facing instance of Floci.\u003c/li\u003e\n\u003cli\u003eThe attacker authenticates or interacts with the public API endpoint, specifically targeting the REST API integration management interface.\u003c/li\u003e\n\u003cli\u003eThe attacker creates a new MOCK integration via the Floci REST API.\u003c/li\u003e\n\u003cli\u003eThe attacker provides a custom Velocity template containing reflective payload syntax targeting 'java.lang.Runtime' or 'java.lang.ProcessBuilder'.\u003c/li\u003e\n\u003cli\u003eThe Floci application saves and subsequently evaluates the malicious template within the VtlTemplateEngine.\u003c/li\u003e\n\u003cli\u003eThe VtlTemplateEngine executes the reflected code within the JVM context.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves arbitrary command execution on the underlying host operating system.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary system commands, leading to complete compromise of the Floci application host. Potential outcomes include full data exfiltration, persistent unauthorized access, lateral movement within the network, and the deployment of additional malware or ransomware.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized, concrete actions for detection engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Floci to version 2.2.0 or later to patch CVE-2026-108598.\u003c/li\u003e\n\u003cli\u003eIf patching cannot be performed immediately, restrict network access to the Floci API management interface to trusted internal segments only.\u003c/li\u003e\n\u003cli\u003eMonitor webserver access logs for anomalous POST requests directed at API integration endpoints, specifically looking for Velocity template syntax or reflective Java keywords in request bodies.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T19:55:48Z","date_published":"2026-10-10T19:55:48Z","id":"https://feed.craftedsignal.io/briefs/2026-10-floci-rce/","summary":"An unauthenticated remote code execution vulnerability in Floci 1.1.0-2.1.9 allows attackers to achieve command execution via malicious Velocity templates.","title":"Remote Code Execution in Floci VtlTemplateEngine","url":"https://feed.craftedsignal.io/briefs/2026-10-floci-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:floci:floci:1.1.0:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}