CVE-2026-68536: Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
Apache MyFaces discloses moderate SSRF and local file inclusion vulnerability CVE-2026-68536 affecting all maintained 2.2 through 4.1 branches.
Apache MyFaces (org.apache.myfaces.core:myfaces-impl) disclosed CVE-2026-68536, a server-side request forgery and local file inclusion vulnerability rated moderate. Affected versions include the 2.2.*, 2.3.*, 3.0.*, 4.0.*, 4.1.* and 2.3-next-* branches. No exploitation details or patch status were provided in the disclosure.
- Server-side request forgery and local file inclusion flaw in the MyFaces JSF implementation.
- All maintained branches affected: 2.2, 2.3, 3.0, 4.0, 4.1 and 2.3-next.
- Severity rated moderate by the Apache MyFaces team; no exploitation reported.
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-68536 | NVD description · AI analysis pending | — | — | — | — | — |
Posted by Volodymyr Siedlecki on Sep 16 Severity: moderate Affected versions: - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 2.2.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 2.3.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 3.0.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 4.0.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 4.1.* - Apache MyFaces (org.apache.myfaces.core:myfaces-impl) 2.3-next-* Description: Server-Side...
This source does not provide full text. Read it at seclists.org.