CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
Apache MyFaces discloses moderate SSRF and local file inclusion vulnerability CVE-2026-68536 affecting all maintained 2.2 through 4.1 branches.
Apache MyFaces (org.apache.myfaces.core:myfaces-impl) disclosed CVE-2026-68536, a server-side request forgery and local file inclusion vulnerability rated moderate. Affected versions include the 2.2.*, 2.3.*, 3.0.*, 4.0.*, 4.1.* and 2.3-next-* branches. No exploitation details or patch status were provided in the disclosure.