CVE-2026-15560

when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-11 09:17

Updated : 2026-09-01 15:17


NVD link : CVE-2026-15560

Mitre link : CVE-2026-15560

CVE.ORG link : CVE-2026-15560


JSON object : View

Products Affected

No product.

CWE
CWE-829

Inclusion of Functionality from Untrusted Control Sphere