CVE-2026-68536

Apache Software Foundation · Apache MyFaces

Apache MyFaces Core is vulnerable to Server-Side Request Forgery and Local File Inclusion, which could allow an unauthenticated attacker to compromise system integrity.

Executive summary

A critical vulnerability in Apache MyFaces Core allows unauthenticated attackers to perform Server-Side Request Forgery and Local File Inclusion, posing a severe risk to system security.

Vulnerability

The software is susceptible to Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI) due to improper input validation in Apache MyFaces Core. This flaw allows an unauthenticated, remote attacker to manipulate requests, potentially leading to unauthorized local file access or interaction with internal network resources.

Business impact

The potential for unauthorized file access and SSRF represents a high-risk scenario for organizational data, as it may lead to the exposure of sensitive configuration files or credentials. With a CVSS score of 9.8, this vulnerability is considered critical because it is fully automatable and requires no authentication, facilitating large-scale exploitation and potential full system compromise.

Remediation

Immediate Action: Upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which contain the necessary security patches.

Proactive Monitoring: Review application and network logs for unusual outbound requests to internal addresses or patterns indicative of path traversal attempts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules designed to detect and block malicious patterns associated with SSRF and path traversal attacks while the update is being staged.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the critical CVSS severity and the potential for unauthenticated remote exploitation, this vulnerability requires immediate attention. Security teams should prioritize patching affected Apache MyFaces instances across the environment to prevent potential data exfiltration or unauthorized system access.

More Apache Software Foundation CVEs

History

CVE Brief tracked this CVE 1 day before it had a CVSS score.

  1. Disclosed CVE record published
  2. Collected by CVE Brief No CVSS score yet; tracked as early warning
  3. CVSS score assigned 9.8 (3.1)
  4. Analyst report written

Sources