AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15555

HIGH · CVSS 8.8 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability in JBoss marshalling allows for remote code execution (RCE) through deserialization of replicated session data without class filtering, affecting all nodes in an Infinispan cluster. This flaw poses a significant risk, as it can be exploited to execute arbitrary code across the entire cluster. Organizations using JBoss with Infinispan should prioritize patching this vulnerability to mitigate potential attacks.

CVE
CVE-2026-15555
Severity
HIGH
CVSS
8.8
EPSS
0.26%

Original NVD Description

A flaw was found in JBoss marshalling. The Infinispan session replication path deserializes replicated session data via the JBoss Marshalling River unmarshaller with no class filtering — enabling RCE via deserialization gadget chains on every cluster node.