CVE-2026-3967
Last modified
CVE-2026-3967 is a medium-severity vulnerability rated 6.3/10 on the CVSS scale. A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization System. EPSS estimates a 0.24% chance of exploitation in the next 30 days.
Description
A flaw has been found in Alfresco Activiti up to 7.19/8.8.0. Affected by this issue is the function deserialize/createObjectInputStream of the file activiti-core/activiti-engine/src/main/java/org/activiti/engine/impl/variable/SerializableType.java of the component Process Variable Serialization System. This manipulation causes deserialization. Remote exploitation of the attack is possible. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-3967?
How severe is CVE-2026-3967?
How do I fix CVE-2026-3967?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-39664Missing Authorization vulnerability in leadrebel Leadrebel l…5.3
- CVE-2026-39665Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-39666Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-39667Improper Neutralization of Input During Web Page Generation …5.9
- CVE-2026-39668Missing Authorization vulnerability in g5theme Book Previewe…5.3
- CVE-2026-39669Missing Authorization vulnerability in NitroPack allows Expl…5.3
- CVE-2026-39670Server-Side Request Forgery (SSRF) vulnerability in Brecht V…6
- CVE-2026-39671Cross-Site Request Forgery (CSRF) vulnerability in Dotstore …7.1
- CVE-2026-39672Missing Authorization vulnerability in shiptime ShipTime: Di…5.3
- CVE-2026-39673Missing Authorization vulnerability in shrikantkale iZooto i…5.3
- CVE-2026-39674Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2026-39675Missing Authorization vulnerability in webmuehle Court Reser…5.3
Are you affected by CVE-2026-3967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
