{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/openequella/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:openequella:openequella:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-67615"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["openEQUELLA (\u003c 2026.1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["openEQUELLA"],"content_html":"\u003cp\u003eopenEQUELLA versions prior to 2026.1.0 are vulnerable to authenticated remote code execution (CVE-2026-67615). The flaw resides in the HTTP invoker endpoint (/invoker/*), which fails to safely handle Java deserialization. Authenticated non-guest users can exploit this by sending a specially crafted serialized object. The implementation uses a PluginAwareObjectInputStream with a class-name denylist; however, attackers bypass this restriction by nesting a malicious payload within a java.security.SignedObject. This wrapping forces the inner stream to be processed by a secondary ObjectInputStream that lacks the required filtering, allowing the payload to reach a JNDI sink. Successful exploitation results in arbitrary code execution within the context of the openEQUELLA service. This vulnerability highlights the risks associated with Java deserialization and the limitations of denylist-based security controls. Organizations using openEQUELLA should upgrade to version 2026.1.0 or later immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker obtains valid non-guest authenticated access to the target openEQUELLA instance.\u003c/li\u003e\n\u003cli\u003eAttacker prepares a malicious serialized Java object payload targeting a known JNDI sink.\u003c/li\u003e\n\u003cli\u003eAttacker wraps the malicious serialized object within a java.security.SignedObject.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP POST request to the application's /invoker/* endpoint containing the crafted object.\u003c/li\u003e\n\u003cli\u003eThe application endpoint receives the request and triggers the PluginAwareObjectInputStream.\u003c/li\u003e\n\u003cli\u003eThe initial deserialization processes the SignedObject; the embedded inner stream bypasses the class-name denylist filter.\u003c/li\u003e\n\u003cli\u003eThe secondary ObjectInputStream deserializes the nested malicious payload.\u003c/li\u003e\n\u003cli\u003eThe JNDI sink is triggered, leading to arbitrary code execution on the application server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to execute arbitrary code on the underlying host, potentially leading to full system compromise, data theft, or lateral movement within the environment. This vulnerability affects all deployments of openEQUELLA prior to 2026.1.0. Given the high CVSS score of 8.8, immediate patching is recommended for all affected instances.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all openEQUELLA instances to version 2026.1.0 or later to mitigate CVE-2026-67615.\u003c/li\u003e\n\u003cli\u003eMonitor HTTP invoker traffic to the /invoker/* endpoint for unusual or excessively large serialized object payloads.\u003c/li\u003e\n\u003cli\u003eRestrict access to the openEQUELLA application to trusted users to reduce the potential for exploitation by malicious or compromised accounts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-22T22:40:20Z","date_published":"2026-09-22T22:40:20Z","id":"https://feed.craftedsignal.io/briefs/2026-09-openequella-rce/","summary":"openEQUELLA versions prior to 2026.1.0 contain a critical authenticated remote code execution vulnerability involving insecure Java deserialization via the /invoker/* endpoint.","title":"Authenticated RCE in openEQUELLA via Deserialization Bypass","url":"https://feed.craftedsignal.io/briefs/2026-09-openequella-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenEQUELLA","version":"https://jsonfeed.org/version/1.1"}