AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66256

HIGH · CVSS 7.2 EPSS 0.52% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-13 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

Apache Shindig is vulnerable to a deserialization of untrusted data issue, allowing users with access to the Shindig REST API to execute arbitrary code on the server through specially-crafted requests. Given that this project is retired and no fix will be released, organizations still using Shindig should prioritize finding an alternative solution or restrict access to the API to trusted users only.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
arbitrary code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-66256
Severity
HIGH
CVSS
7.2
EPSS
0.52%
Apache

Original NVD Description

** UNSUPPORTED WHEN ASSIGNED ** Deserialization of Untrusted Data vulnerability in Apache Shindig. This issue affects Apache Shindig: all versions. Users with access to the Shindig REST API can send specially-crafted requests to trigger arbitrary code execution on the server. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.