CVE-2026-68536
Apache Software Foundation · Apache MyFaces
Apache MyFaces Core is vulnerable to Server-Side Request Forgery and Local File Inclusion, which could allow an unauthenticated attacker to compromise system integrity.
Executive summary
A critical vulnerability in Apache MyFaces Core allows unauthenticated attackers to perform Server-Side Request Forgery and Local File Inclusion, posing a severe risk to system security.
Vulnerability
The software is susceptible to Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI) due to improper input validation in Apache MyFaces Core. This flaw allows an unauthenticated, remote attacker to manipulate requests, potentially leading to unauthorized local file access or interaction with internal network resources.
Business impact
The potential for unauthorized file access and SSRF represents a high-risk scenario for organizational data, as it may lead to the exposure of sensitive configuration files or credentials. With a CVSS score of 9.8, this vulnerability is considered critical because it is fully automatable and requires no authentication, facilitating large-scale exploitation and potential full system compromise.
Remediation
Immediate Action: Upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which contain the necessary security patches.
Proactive Monitoring: Review application and network logs for unusual outbound requests to internal addresses or patterns indicative of path traversal attempts.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block malicious patterns associated with SSRF and path traversal attacks while the update is being staged.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the critical CVSS severity and the potential for unauthenticated remote exploitation, this vulnerability requires immediate attention. Security teams should prioritize patching affected Apache MyFaces instances across the environment to prevent potential data exfiltration or unauthorized system access.
More Apache Software Foundation CVEs
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 9.8 (3.1)
- Analyst report written