CVE-2026-71374
Unauthenticated Deserialization Flaw in Hitachi Cosminexus Component Container
CVE-2026-71374 is a deserialization of untrusted data flaw (CWE-502) in the Cosminexus Component Container, the Java application server runtime in Hitachi's Cosminexus middleware stack. An attacker who can reach the component's network-facing interface can supply maliciously crafted serialized data, which is deserialized without authentication (CVSS vector AV:N/AC:L/PR:N/UI:N). Successful exploitation plausibly yields remote code execution or full compromise of confidentiality, integrity and availability, consistent with the critical 9.8 base score. All maintained 09-x and 11-x release streams listed in the advisory are affected, meaning long-lived enterprise deployments on older update levels are exposed. No public proof-of-concept or in-the-wild exploitation is currently known, is not in CISA KEV, and EPSS assigns a low 0.3% probability of exploitation within 30 days.
What to do: Apply Hitachi's fixed update levels: upgrade to 11-70-03 or later, 11-60-03 or later, 11-20-10 or later, 11-00-13 or later, 09-87-10 or later, 09-80-05 or later, or 09-70-28 or later as applicable, and consult the Hitachi advisory for the exact fixed release superseding the affected ranges expressed as 'through' values (e.g., 11-50-03, 09-50-22, 09-00-18). Until patching, restrict network access to the Component Container's service ports to trusted hosts only. Inventory running Cosminexus versions and prioritize internet-reachable or third-party-reachable instances.
| Hitachi Cosminexus Component Container | 09-00 through 09-00-18; 09-50 through 09-50-22; 09-70 before 09-70-28; 09-80 before 09-80-05; 09-87 before 09-87-10; 11-00 before 11-00-13; 11-10 through 11-10- |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Deserialization of untrusted data vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.