SEPTEMBER 25, 2026
Live Feed
Back to database
Case File

CVE-2026-91866

HIGH · CVSS 7.5 EPSS 0.49%

Source: NVD + CISA KEV + EPSS · Published 2026-09-21 · Last synced 2026-09-25

CyberRota Analysis

AI-Generated

This vulnerability affects systems utilizing Neethi's policy-intersection functionality, where specially crafted WS-Policy documents can trigger excessive CPU usage, leading to a denial of service. Organizations relying on Neethi for policy management should prioritize upgrading to version 3.2.4 to mitigate the risk of service disruption.

CVE
CVE-2026-91866
Severity
HIGH
CVSS
7.5
EPSS
0.49%

Original NVD Description

A specially crafted pair of WS-Policy documents can force Neethi's policy-intersection to do exponential amounts of work, pinning the CPU for a long time (denial of service). Users are recommended to upgrade to version 3.2.4, which fixes this issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)