SB20260825109 - Deserialization of Untrusted Data in Apache Camel
Published: August 25, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Deserialization of Untrusted Data (CVE-ID: CVE-2026-40858)
CWE-ID: CWE-502 - Deserialization of Untrusted Data
CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to unsafe deserialization in the ProtoStream-based remote aggregation repository of the camel-infinispan component when deserializing data read from a remote Infinispan cache during aggregation repository operations. A remote user can write a crafted serialized Java object to the cache to execute arbitrary code.
Exploitation requires the ability to write to the Infinispan cache used by the application.
Remediation
Install update from vendor's website.