OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94109

HIGH · CVSS 8 EPSS 0.78% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-20 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Versions of openEQUELLA prior to 2026.1.0 are vulnerable to a remote code execution flaw stemming from an unsandboxed TemplateClassResolver configuration in FreeMarker template compilation. This allows authenticated attackers to inject malicious template expressions, potentially executing arbitrary commands on the server. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94109
Severity
HIGH
CVSS
8
EPSS
0.78%

Original NVD Description

openEQUELLA before 2026.1.0 contains an authenticated stored server-side template injection vulnerability in FreemarkerPortletRenderer.renderHtml() that allows any authenticated non-guest user to achieve remote code execution by storing a malicious FreeMarker payload through a POST request to the RemotePortletService invoker endpoint. The markup field from stored portlet configuration is passed directly to custFactory.createResult() without a TemplateClassResolver restriction or FreeMarker sandboxing in BasicConfiguration, leaving built-ins such as ?new and freemarker.template.utility.Execute available, causing the payload to execute in the application server process context when any user renders a dashboard containing the affected portlet.