CVE-2026-6857
A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.
- Affected products
- Camel-Infinispan
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 0.7% (49th percentile)
- Weakness
- CWE-502
- NVD status
- Awaiting Analysis
- Published
- 2026-04-22
Workaround
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
CVE-2026-6857 at NVD
2 known exploits for CVE-2026-6857
Proof-of-concept code and exploit modules indexed by Sploitus