---
cve: "CVE-2026-66713"
severity: "CRITICAL"
cvss: 9.8
epss: "1.8%"
vendor: "Apache Software Foundation"
kev: false
exploited: false
published: "2026-07-28 15:17:50"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T22:00:16+02:00"
---

# CVE-2026-66713

> 9.8 CRITICAL · 🧪 PoC

## Beschreibung

Deserialization of Untrusted Data (CWE-502) in the Tribes-based clustering component

  in Apache Software Foundation Apache Axis2/Java through 2.0.0 on Apache Tomcat

  (only when Tribes clustering is enabled, which is off by default) allows an

  unauthenticated remote attacker with network access to the clustering port to

  execute arbitrary code via a crafted serialized Java object delivered to the cluster

  channel and deserialized in

  org.apache.axis2.clustering.tribes.Axis2ChannelListener#messageReceived. Users are

  recommended to upgrade to version 2.0.1, which fixes this issue by removing the

  clustering feature entirely.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-502** — Deserialization of Untrusted Data
  The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

## Angriffsmuster (CAPEC)

- [CAPEC-586 — Object Injection](https://capec.mitre.org/data/definitions/586.html) _(Severity: High)_

## Patch verfügbar (OSV)

- 24fcdf42bbc70a5dcfa77df9e2f5e9a8c13f4dfe (Commit)
- e6f53b230bddcb40577c84ff290ba51e7265fa15 (Commit)

## Referenzen

- <https://github.com/apache/axis-axis2-java-core/commit/e6f53b230bddcb40577c84ff290ba51e7265fa15>
- <https://lists.apache.org/thread/fgggbv3sjjqw7p6q0j88gspt9b2rb728>
- <http://www.openwall.com/lists/oss-security/2026/07/28/2>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-66713) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
