SB20260825109 - Deserialization of Untrusted Data in Apache Camel



SB20260825109 - Deserialization of Untrusted Data in Apache Camel

Published: August 25, 2026

Security Bulletin ID SB20260825109
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Deserialization of Untrusted Data (CVE-ID: CVE-2026-40858)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to unsafe deserialization in the ProtoStream-based remote aggregation repository of the camel-infinispan component when deserializing data read from a remote Infinispan cache during aggregation repository operations. A remote user can write a crafted serialized Java object to the cache to execute arbitrary code.

Exploitation requires the ability to write to the Infinispan cache used by the application.


Remediation

Install update from vendor's website.