CVE-2026-57527
Last modified
CVE-2026-57527 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The JSFViewState.decode() method base64-decodes the ViewState value and passes it directly to ObjectInputStream.readObject() without a deserialization filter, allowlist, or type restriction, causing the malicious object to be deserialized within the ZAP JVM when the Desktop UI renders the ViewState panel.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution by embedding a malicious serialized Java object in the javax.faces.ViewState HTTP response parameter. The JSFViewState.decode() method base64-decodes the ViewState value and passes it directly to ObjectInputStream.readObject() without a deserialization filter, allowlist, or type restriction, causing the malicious object to be deserialized within the ZAP JVM when the Desktop UI renders the ViewState panel.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| zaproxy | zap-extensions | < 4 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-57527?
How severe is CVE-2026-57527?
How do I fix CVE-2026-57527?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5752Sandbox Escape Vulnerability in Terrarium allows arbitrary c…9.3
- CVE-2026-57520Bitwarden Server before 2026.5.0 contains a privilege escala…7.1
- CVE-2026-57521Bitwarden Server before 2026.5.0 contains a broken access co…5.3
- CVE-2026-57522Bitwarden Server before 2026.5.0 contains a JSON injection v…5
- CVE-2026-57523Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-57525Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-5753The All-in-One WP Migration Unlimited Extension plugin for W…6.5
- CVE-2026-57530Milkdown before 7.21.3 contains a stored cross-site scriptin…5.4
- CVE-2026-57531Milkdown before 7.21.3 contains a DOM cross-site scripting v…5.4
- CVE-2026-57532Malicious HTML content contained in the layout specification…8.8
- CVE-2026-57533Malicious HTML content could be injected into the page preti…2.1
- CVE-2026-57534Malicious HTML content could be injected into the content of…2.1
Are you affected by CVE-2026-57527?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
