{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aredhatquarkus/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:redhat:quarkus:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-12894"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Quarkus"],"_cs_severities":["high"],"_cs_tags":["vulnerability","rce","java","quarkus"],"_cs_type":"advisory","_cs_vendors":["Red Hat"],"content_html":"\u003cp\u003eCVE-2026-12894 is a critical vulnerability within the Qute template engine, a core component used by Red Hat Quarkus for generating dynamic content such as HTML pages and emails. The vulnerability resides in the ReflectionValueResolver, which acts as a bridge for accessing data properties within templates. Due to improper validation logic, the engine fails to restrict access to sensitive Java internal functions when processing specific data types, particularly Enums.\u003c/p\u003e\n\u003cp\u003eAn attacker who can provide or influence the input rendered by a template can exploit this flaw to escape the intended sandbox and invoke unauthorized Java methods. This allows for arbitrary command execution on the host server. This vulnerability is significant for environments leveraging Quarkus for user-controllable dynamic rendering, where input sanitization might be insufficient to prevent the injection of malicious template expressions. Organizations should prioritize updating Quarkus and reviewing custom template implementations that accept untrusted user input.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthenticated attackers to achieve remote code execution on the server hosting the Quarkus application. This can lead to full system compromise, data exfiltration, or the deployment of persistent threats within the application environment. The severity is high (CVSS 8.8), reflecting the ease of exploitation once an attacker has the ability to provide input to the template rendering process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Quarkus to the latest patched release that incorporates the fix for the ReflectionValueResolver component.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing Qute templates to identify endpoints that process untrusted user input; implement strict input validation and sandboxing.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for anomalous POST requests or inputs containing template expressions involving Enums or reflection-related keywords.\u003c/li\u003e\n\u003cli\u003eReview application code for custom resolvers that may be mirroring the insecure behavior documented in CVE-2026-12894.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T13:58:58Z","date_published":"2026-08-31T13:58:58Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-12894-quarkus/","summary":"The Qute template engine in Quarkus fails to properly restrict access to sensitive Java internals, allowing an attacker to achieve remote code execution via template injection.","title":"Remote Code Execution in Quarkus via Qute Template Engine","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-12894-quarkus/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:redhat:quarkus:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}