CVE-2026-66909
Last modified
CVE-2026-66909 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution.
Description
Apache CXF's JMS transport deserializes the body of any inbound JMS ObjectMessage using native Java deserialization, with no type restrictions in place. Any attacker able to place a message on the service's JMS destination can submit a malicious serialized object, leading to denial of service or, if a suitable gadget class is on the classpath, remote code execution. The fix disables ObjectMessage deserialization by default, with a configuration switch to re-enable it if needed. Users are recommended to upgrade to versions 4.2.3 or 4.1.8 or 3.6.12, which fix this issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Cxf | < 3.6.12 |
| Apache | Cxf | >= 4.0.0, < 4.1.8 |
| Apache | Cxf | >= 4.2.0, < 4.2.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2026-66909?
How severe is CVE-2026-66909?
How do I fix CVE-2026-66909?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-6690The LifePress plugin for WordPress is vulnerable to Stored C…7.2
- CVE-2026-66901Google::Auth versions before 0.09 for Perl allow server side…7.5
- CVE-2026-66902Google::Auth versions before 0.06 for Perl run a command nam…9.8
- CVE-2026-66906Relative path traversal vulnerability in Apache Camel Azure …9.1
- CVE-2026-66907Relative path traversal vulnerability in Apache Camel Google…7.5
- CVE-2026-66908Improper Authentication vulnerability in Apache Camel Platfo…7.5
- CVE-2026-6691The MongoDB C Driver's Cyrus SASL integration performs unsaf…8.6
- CVE-2026-66913Lookyloo did not enforce limits on the decompressed size of …6.9
- CVE-2026-66914Joomla Extension - seblod.com - Unauthenticated path travers…9.2
- CVE-2026-66915Joomla Extension - fabrikar.com - Remote code execution in F…10
- CVE-2026-66916Joomla Extension - joomgalleryfriends.net - Password-Protect…6.9
- CVE-2026-66917Joomla Extension - joomgalleryfriends.net - Stored XSS in Jo…8.6
Are you affected by CVE-2026-66909?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
