{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/openequella--2026.1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:apereo:openequella:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-94109"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openEQUELLA (\u003c 2026.1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Apereo Foundation"],"content_html":"\u003cp\u003eApereo Foundation's openEQUELLA versions prior to 2026.1.0 contain a critical remote code execution (RCE) vulnerability stemming from the insecure configuration of the FreeMarker template engine. The application fails to properly sandbox the TemplateClassResolver during template compilation. This allows authenticated users with access to administrative or content-management interfaces - such as the creation of collection summaries, dashboard portlets, or MIME templates - to inject malicious FreeMarker expressions. By exploiting this, an attacker can instantiate sensitive Java classes, specifically \u003ccode\u003efreemarker.template.utility.Execute\u003c/code\u003e, to invoke \u003ccode\u003eRuntime.exec\u003c/code\u003e on the underlying host operating system. This vulnerability allows for full system command execution within the context of the service account running the openEQUELLA application. Given the nature of the application as a digital repository, defenders should focus on monitoring administrative actions and input fields that allow for template or script-like data entry.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability allows an authenticated attacker to execute arbitrary code with the privileges of the application server. This could lead to a full system compromise, exfiltration of sensitive repository data, or the deployment of persistent malware. Affected sectors include higher education and research institutions that rely on openEQUELLA for digital asset management.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of openEQUELLA to version 2026.1.0 or later to apply the necessary security patches for FreeMarker configuration.\u003c/li\u003e\n\u003cli\u003eAudit application access logs for unusual administrative activity, particularly involving the creation or modification of collection summaries, dashboard portlets, or MIME templates.\u003c/li\u003e\n\u003cli\u003eLimit the creation of content templates and dashboard portlets to highly trusted administrative roles to minimize the attack surface until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-20T12:21:51Z","date_published":"2026-09-20T12:21:51Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openequella-rce/","summary":"Authenticated users can achieve remote code execution in openEQUELLA versions prior to 2026.1.0 by leveraging an unsandboxed FreeMarker configuration to execute arbitrary system commands.","title":"Remote Code Execution in openEQUELLA via FreeMarker Template Injection","url":"https://feed.craftedsignal.io/briefs/2026-09-openequella-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenEQUELLA (\u003c 2026.1.0)","version":"https://jsonfeed.org/version/1.1"}