CVE-2026-91842

A vulnerability has been found in OpenBankProject OBP-API up to 1.10.1. This impacts the function KryoInjection.invert of the file obp-api/src/main/scala/code/api/cache/Redis.scala of the component Kryo Handler. Such manipulation leads to deserialization. The attack can be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-15 15:17

Updated : 2026-09-15 16:17


NVD link : CVE-2026-91842

Mitre link : CVE-2026-91842

CVE.ORG link : CVE-2026-91842


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation

CWE-502

Deserialization of Untrusted Data