CVE-2026-86404

8.8

Red Hat · JBoss Enterprise Application Platform

A deserialization vulnerability exists in the Artemis component of JBoss EAP 7.4, allowing unauthorized classes to be deserialized due to improperly configured allow-lists and block-lists.

Executive summary

A critical deserialization vulnerability in Red Hat JBoss Enterprise Application Platform 7.4 allows authenticated attackers to potentially execute arbitrary code on the host system.

Vulnerability

This is a deserialization of untrusted data (CWE-502) vulnerability where the Artemis configuration fails to enforce security filtering. An authenticated attacker can leverage this oversight to bypass class restrictions and trigger arbitrary deserialization.

Business impact

The ability to perform arbitrary deserialization poses a severe risk of remote code execution, potentially leading to a total system compromise. Given the CVSS score of 8.8, this vulnerability represents a high risk to the confidentiality, integrity, and availability of sensitive business applications and their underlying data.

Remediation

Immediate Action: Update to the fixed versions provided by Red Hat, specifically ensuring components are upgraded to the versions listed in the RHSA-2026:53644 security advisory.

Proactive Monitoring: Monitor application logs for unusual deserialization errors, unexpected class loading events, or unauthorized attempts to access system resources.

Compensating Controls: Implement strict network segmentation to limit access to the JBoss management interfaces and utilize runtime application self protection (RASP) tools to detect and block malicious deserialization payloads.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations running Red Hat JBoss Enterprise Application Platform 7.4 ELS on RHEL 7 must prioritize the application of the vendor-provided security patches. Given the potential for remote code execution via deserialization, swift remediation is essential to prevent unauthorized access and potential data exfiltration.

More Red Hat CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources