Lightstreamer Server 7.4.8 JMX flaws disclosed
Lightstreamer Server 7.4.8 JMX flaws can enable remote or native code execution; reports disagree on score and access path, and neither names a CVE.
Two Full Disclosure posts dated 2026-09-27 describe serious JMX issues in Lightstreamer Server 7.4.8 build 3506 with JMS Extender 2.1.0. One report says the Enterprise distribution ships placeholder JMX/RMI credentials and exposes a cleartext RMI management connector on TCP 8888 bound to every interface, which can lead to remote class loading and root remote code execution, scored 9.8. The other, from the 0day Rubbish Research Team, says an anonymous caller can use the JMX inspection console to invoke MBean operations, including loading a native agent into the broker JVM, scored 8.1 and mapped to CWE-306, CWE-345, CWE-20, CWE-250, and CWE-1188. The posts disagree on severity and describe different access conditions—placeholder credentials versus unauthenticated access—and different code-execution mechanisms. Neither report assigns a CVE or claims observed exploitation.
- Affects Lightstreamer Server 7.4.8 Enterprise build 3506 with JMS Extender 2.1.0.
- One 2026-09-27 report says placeholder JMX/RMI credentials and a cleartext RMI connector on TCP 8888, bound to every interface, can enable remote class loading and root remote code execution, scored 9.8.
- A second same-day report from the 0day Rubbish Research Team says unauthenticated JMX access lets an anonymous caller invoke MBean operations, including loading a native agent into the broker JVM, scored 8.1.
- The second report cites CWE-306, CWE-345, CWE-20, CWE-250, and CWE-1188.
- Neither report names a CVE or claims in-the-wild exploitation.
- Sources disagree on the score (9.8 versus 8.1) and describe different access conditions and code-execution paths.
Coverage timelineoldest first · each row is one article
- · 5h ago[0day-rubbish] Lightstreamer Server 7.4.8 Shipped placeholder JMX/RMI credentials plus MLet remote class loading to root RCE (9.8)
Full Disclosure· 62
Lightstreamer Server 7.4.8 ships placeholder JMX credentials that enable remote class loading and root code execution.
- · 5h ago[0day-rubbish] Lightstreamer Server 7.4.8 Unauthenticated JMX jvmtiAgentLoad native code execution (8.1)
Full Disclosure· 48
Researchers disclosed an unauthenticated JMX flaw in Lightstreamer Server 7.4.8 that can load native code in the JVM.