Red HatCVE-2026-15560
Red Hat: untrusted functionality included
High8.1CVE-2026-15560 · Published Aug 11, 2026 · updated Sep 25, 2026
when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attacker-supplied CDR codebase URLs during object unmarshalling on :3528, allowing an unauthenticated attacker to load and instantiate arbitrary classes from a remote URL in the server JVM before EJB security interceptors run.
Affected versions
The source does not list versions here. See the source advisory for affected products and fixes.
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-829
- www.cve.org/CVERecord?id=CVE-2026-15560
- nvd.nist.gov/vuln/detail/CVE-2026-15560
- access.redhat.com/errata/RHSA-2026:53644
- access.redhat.com/errata/RHSA-2026:53645
- access.redhat.com/errata/RHSA-2026:53646
- access.redhat.com/errata/RHSA-2026:53806
- access.redhat.com/errata/RHSA-2026:70228
- access.redhat.com/errata/RHSA-2026:70229
- access.redhat.com/errata/RHSA-2026:70230
- access.redhat.com/errata/RHSA-2026:70277
- access.redhat.com/security/cve/CVE-2026-15560
- bugzilla.redhat.com/show_bug.cgi?id=2483131
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 11 | Red Hat FreeIPA: improper authorization | High8.2 | No fix yet |
| Aug 11 | Red Hat search-v2-api. The authentication middleware: authentication bypass | High7.5 | No fix yet |
| Aug 11 | Red Hat acm-search-v2-api-rhel9.: information disclosure | Medium5.3 | No fix yet |
| Aug 11 | Red Hat insights-client.: information disclosure | High7.1 | No fix yet |
| Aug 11 | Red Hat insights-client. A compromised managed cluster: information disclosure | Medium6.8 | No fix yet |
| Aug 11 | Red Hat insights-client: secrets in logs | Medium6.3 | No fix yet |