CVE-2026-94109

Source
https://cve.org/CVERecord?id=CVE-2026-94109
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94109.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94109
Published
2026-09-20T11:33:55Z
Modified
2026-09-22T08:05:29Z
Severity
  • 8.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
openEQUELLA before 2026.1.0 Remote Code Execution via FreeMarker Template Injection
Details

openEQUELLA versions before 2026.1.0 contain a remote code execution vulnerability in FreeMarker template compilation due to an unsandboxed TemplateClassResolver configuration. Authenticated attackers can inject malicious template expressions through collection summaries, dashboard portlets, or MIME templates to instantiate dangerous classes like freemarker.template.utility.Execute and invoke Runtime.exec for arbitrary command execution.

Database specific
{
    "cna_assigner":  "VulnCheck",
    "cwe_ids":  [
        "CWE-1336"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94109.json"
}
References

Affected packages

Git / github.com/openequella/openequella

Affected ranges

Type
GIT
Repo
https://github.com/openequella/openequella
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2026.1.0"
        }
    ],
    "source":  [
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

2018.*
2018.2-RC1
2018.2-Stable
2019.*
2019.2-RC
2019.2.0
2019.2.1
2020.*
2020.1.0
2020.1.0-RC1
2020.1.1
2020.1.2
2020.1.3
2020.1.4
2020.1.5
2020.1.6
2020.2.0
2021.*
2021.1.0
2021.1.1
2021.1.2
2021.2.0
2021.2.1
2021.2.2
2021.2.3
2022.*
2022.1.0
2022.2.0
2023.*
2023.1.0
2023.2.0
2024.*
2024.1.0
2024.2.0
2025.*
2025.1.0
2025.2.0
6.*
6.4-Alpha
6.4-Beta
6.5-Alpha
6.5-Beta
6.5-Stable
6.6-RC1
6.6-RC2
6.6-Stable
Other
pre-mega-format
start-2019.*
start-2019.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94109.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "function_hash":  "235466883635136193310868589380270201175",
            "length":  182
        },
        "id":  "CVE-2026-94109-24a29d3f",
        "signature_type":  "Function",
        "signature_version":  "v1",
        "source":  "https://github.com/openequella/openequella/commit/d6e165afc986f8a3ed912cdb367d5ad8c1eeab5c",
        "target":  {
            "file":  "Source/Plugins/Core/com.equella.core/src/com/tle/web/freemarker/BasicConfiguration.java",
            "function":  "BasicConfiguration"
        }
    },
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "223743616906910024966792958104291224450",
                "149160298893242027350613654826857682926",
                "250017236842937766004123964826082385450",
                "195829287765834913666734330880432986252",
                "112379631583596739824808054585723787635",
                "128162232043109272978988819419131998866",
                "335123795018919565560418288410742120729",
                "213465060508192380924131533916788154403",
                "82426487824841196634582136901365293029",
                "317001260967976726126168545033004441847",
                "38597487955534090984610422883163611048"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-94109-f1570dfb",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/openequella/openequella/commit/d6e165afc986f8a3ed912cdb367d5ad8c1eeab5c",
        "target":  {
            "file":  "Source/Plugins/Core/com.equella.core/src/com/tle/web/freemarker/BasicConfiguration.java"
        }
    }
]
vanir_signatures_modified
"2026-09-22T08:05:29Z"