CVE-2026-14265
Last modified
CVE-2026-14265 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java object. The RemoteQueryCachePlugin uses ObjectInputStream without class filtering when deserializing cached query results from Redis or Valkey, enabling gadget chain execution when cache entries are poisoned. We recommend upgrading to AWS Advanced JDBC Wrapper version 4.0.1 or later.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java object. The RemoteQueryCachePlugin uses ObjectInputStream without class filtering when deserializing cached query results from Redis or Valkey, enabling gadget chain execution when cache entries are poisoned. We recommend upgrading to AWS Advanced JDBC Wrapper version 4.0.1 or later.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Amazon | Advanced Jdbc Wrapper | >= 3.3.0, < 4.0.1 |
References
- https://aws.amazon.com/security/security-bulletins/2026-051-aws/Release Notes, Vendor Advisory, Mitigation
- https://github.com/aws/aws-advanced-jdbc-wrapper/security/advisories/GHSA-c5q4-97jw-jgghVendor Advisory, Mitigation
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-14265?
How severe is CVE-2026-14265?
How do I fix CVE-2026-14265?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14256ELAN reported a potential out-of-bounds write vulnerability …4.7
- CVE-2026-14257brace-expansion through 5.0.7 is vulnerable to denial of ser…7.5
- CVE-2026-14258A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router …6.5
- CVE-2026-1426The Advanced AJAX Product Filters plugin for WordPress is vu…8.8
- CVE-2026-14261A vulnerability in the Xerte Online Tools allows for authent…9.1
- CVE-2026-14262The Simple JWT Login – Allows you to use JWT on REST endpoin…8.8
- CVE-2026-142667-Zip XZ Decompression Heap-based Buffer Overflow Remote Cod…7.8
- CVE-2026-1427Single Sign-On Portal System developed by WellChoose has a O…8.8
- CVE-2026-14270The Extra Checkout Options (addon for Extra Product Options …8.8
- CVE-2026-14278Rejected reason: After further coordination, CVE was determi…
- CVE-2026-14279The Wholesale Market plugin for WordPress is vulnerable to p…8.8
- CVE-2026-1428Single Sign-On Portal System developed by WellChoose has a O…8.8
Are you affected by CVE-2026-14265?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
