logo

CVE-2026-25526: Critical Jinjava Flaw (CVSS 9.8) Permits Remote Code Execution

ID: 189f8ae9-d2ee-5874-9408-8a7c1aa9786a

STIX ID: report--189f8ae9-d2ee-5874-9408-8a7c1aa9786a

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-02-09

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical vulnerability (CVE-2026-25526, CVSS 9.8) in the Jinjava Java template engine allows attackers who can edit templates to bypass sandbox restrictions—via a ForTag introspection flaw and ObjectMapper deserialization—to instantiate internal contexts and achieve arbitrary Java code execution on servers; maintainers released fixes and recommend upgrading to Jinjava 2.8.3 or 2.7.6+ immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.