AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15563

HIGH · CVSS 7.4 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

A vulnerability exists in the EAP's IIOP listener, which improperly accepts bind operations without authentication, enabling attackers to hijack JNDI lookups and redirect them to a malicious Object Request Broker (ORB). This flaw can lead to man-in-the-middle (MITM) attacks or denial-of-service (DoS) conditions on subsequent invocations. Organizations utilizing EAP should prioritize addressing this issue to safeguard their systems against potential exploitation.

CVE
CVE-2026-15563
Severity
HIGH
CVSS
7.4
EPSS
0.29%

Original NVD Description

A flaw was found in EAP's IIOP. The listener's NameService would accept bind operations without authentication, allowing an attacker to hijack JNDI lookups and binding them to a malicious ORB, achieving MITM or DoS on further invocations.