ZeroHour
oss-securitypublished ()ingested
Part of a story covered by 2 sources: “Apache MyFaces discloses critical DoS flaw (CVE-2026-76646) and moderate SSRF/LFI flaw (CVE-2026-68536)” — merged summary and timeline →

CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability

mediumVulnerabilityimportance 35CVE-2026-68536
AI summary · glm-5.3-flash

Apache MyFaces discloses moderate SSRF and local file inclusion vulnerability CVE-2026-68536 affecting all maintained 2.2 through 4.1 branches.

Apache MyFaces (org.apache.myfaces.core:myfaces-impl) disclosed CVE-2026-68536, a server-side request forgery and local file inclusion vulnerability rated moderate. Affected versions include the 2.2.*, 2.3.*, 3.0.*, 4.0.*, 4.1.* and 2.3-next-* branches. No exploitation details or patch status were provided in the disclosure.

  • Server-side request forgery and local file inclusion flaw in the MyFaces JSF implementation.
  • All maintained branches affected: 2.2, 2.3, 3.0, 4.0, 4.1 and 2.3-next.
  • Severity rated moderate by the Apache MyFaces team; no exploitation reported.
VendorsApache

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-68536

NVD description · AI analysis pending
Full article

Posted by Volodymyr Siedlecki on Sep 16 Severity: moderate Affected versions: - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 2.2.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 2.3.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 3.0.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 4.0.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 4.1.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 2.3-next-* Description: Server-Side...

This source does not provide full text. Read it at seclists.org.