CVE-2026-15538

Source
https://cve.org/CVERecord?id=CVE-2026-15538
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15538.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-15538
Aliases
  • GHSA-hgqw-899r-rc46
Published
2026-07-13T06:00:11Z
Modified
2026-08-29T03:46:08Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X CVSS Calculator
Summary
primefaces primereact API ObjectUtils.js ObjectUtils.mutateFieldData prototype pollution
Details

A weakness has been identified in primefaces primereact up to 10.9.8. This issue affects the function ObjectUtils.mutateFieldData of the file components/lib/utils/ObjectUtils.js of the component API. This manipulation of the argument Field causes improperly controlled modification of object prototype attributes. The attack is possible to be carried out remotely. Upgrading to version 10.9.9 and 11.0.0 is capable of addressing this issue. Patch name: 61f182e11d9ef52032ff56f420da763a6938236f. It is recommended to upgrade the affected component.

Database specific
{
    "cna_assigner": "VulDB",
    "cwe_ids": [
        "CWE-1321",
        "CWE-94"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/15xxx/CVE-2026-15538.json"
}
References

Affected packages

Git / github.com/primefaces/primereact

Affected ranges

Type
GIT
Repo
https://github.com/primefaces/primereact
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "10.9.0"
        },
        {
            "last_affected": "10.9.0"
        },
        {
            "introduced": "10.9.1"
        },
        {
            "last_affected": "10.9.1"
        },
        {
            "introduced": "10.9.2"
        },
        {
            "last_affected": "10.9.2"
        },
        {
            "introduced": "10.9.3"
        },
        {
            "last_affected": "10.9.3"
        },
        {
            "introduced": "10.9.4"
        },
        {
            "last_affected": "10.9.4"
        },
        {
            "introduced": "10.9.5"
        },
        {
            "last_affected": "10.9.5"
        },
        {
            "introduced": "10.9.6"
        },
        {
            "last_affected": "10.9.6"
        },
        {
            "introduced": "10.9.7"
        },
        {
            "last_affected": "10.9.7"
        },
        {
            "introduced": "10.9.8"
        },
        {
            "last_affected": "10.9.8"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

10.*
10.9.0
10.9.1
10.9.2
10.9.3
10.9.4
10.9.5
10.9.6
10.9.7
10.9.8

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-15538.json"