CVE-2026-6857

Source
https://cve.org/CVERecord?id=CVE-2026-6857
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6857.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-6857
Aliases
Published
2026-04-22T12:55:00.791Z
Modified
2026-08-28T11:30:45.598733162Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Camel-infinispan: camel-infinispan: remote code execution via unsafe deserialization
Details

A flaw was found in camel-infinispan. This vulnerability involves unsafe deserialization in the ProtoStream remote aggregation repository. A remote attacker with low privileges could exploit this by sending specially crafted data, leading to arbitrary code execution. This allows the attacker to gain full control over the affected system, impacting its confidentiality, integrity, and availability.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/6xxx/CVE-2026-6857.json",
    "cwe_ids": [
        "CWE-502"
    ],
    "cna_assigner": "redhat"
}
References

Affected packages

Git / github.com/apache/camel

Affected ranges

Type
GIT
Repo
https://github.com/apache/camel
Events
Database specific
Show details
{
    "source": "AFFECTED_FIELD",
    "extracted_events": [
        {
            "introduced": "4.0.0"
        },
        {
            "fixed": "4.14.7"
        },
        {
            "introduced": "4.15.0"
        },
        {
            "fixed": "4.18.2"
        },
        {
            "introduced": "4.19.0"
        },
        {
            "fixed": "4.20.0"
        }
    ]
}

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-6857.json"