SB2026100258 - Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component



SB2026100258 - Multiple vulnerabilities in IBM Maximo Application Suite - Monitor Component

Published: October 2, 2026

Security Bulletin ID SB2026100258
CSH Severity
High
Patch available
NO
Number of vulnerabilities 49
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

High 12% Medium 65% Low 22%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 49 vulnerabilities.


1) Improper Authentication (CVE-ID: CVE-2026-42010)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper authentication in RSA-PSK username matching when processing usernames containing a NUL character. A remote attacker can supply a specially crafted username to bypass authentication.


2) Resource exhaustion (CVE-ID: CVE-2025-59375)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote attacker can trigger large dynamic memory allocations via a small document and perform a denial of service (DoS) attack.


3) Heap-based buffer overflow (CVE-ID: CVE-2026-5450)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to calling the scanf family of functions with a %mc (malloc'd character match) in the GNU C Library with a format width specifier with an explicit width greater than 1024 could result in a one byte heap buffer overflow. A remote attacker can pass specially crafted data to the application, trigger a heap-based buffer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


4) Improper Resource Shutdown or Release (CVE-ID: CVE-2026-22740)

CWE-ID: CWE-404 - Improper Resource Shutdown or Release

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper resource management in multipart request handling in WebFlux when processing multipart requests. A remote user can send a series of multipart requests to consume available disk space.

Temp files created for parts larger than 10 K may remain undeleted after request processing under some circumstances.


5) Generation of Predictable Numbers or Identifiers (CVE-ID: CVE-2026-41838)

CWE-ID: CWE-340 - Generation of Predictable Numbers or Identifiers

CVSSv4: 5.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to the use of predictable session identifiers in the spring-websocket module when establishing WebSocket sessions. A remote user can predict session IDs to disclose sensitive information.

Exploitation may be possible in combination with inadequate authorization rules, and user interaction is required.


6) Session Fixation (CVE-ID: CVE-2026-41839)

CWE-ID: CWE-384 - Session Fixation

CVSSv4: 1.8 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information and modify data associated with an authenticated user's session.

The vulnerability exists due to improper session management in the WebFlux session handling mechanism when processing requests from a compromised subdomain. A remote attacker can exchange a known session ID for that of an authenticated user to disclose sensitive information and modify data associated with an authenticated user's session.

Exploitation requires user interaction and a compromised subdomain, for example through cross-site scripting.


7) Memory leak (CVE-ID: CVE-2026-41840)

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to memory leakage in multipart request processing in Spring WebFlux when processing multipart requests. A remote attacker can send malicious multipart requests to cause a denial of service.

The issue affects applications that implement a web endpoint that receives multipart requests.


8) Deserialization of Untrusted Data (CVE-ID: CVE-2026-41855)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform unauthorized actions.

The vulnerability exists due to unsafe deserialization in org.springframework.jms.support.converter.MappingJackson2MessageConverter and org.springframework.jms.support.converter.JacksonJsonMessageConverter when processing messages in an untrusted JMS environment. A remote attacker can send a crafted message to perform unauthorized actions.

Exploitation can lead to arbitrary class instantiation through gadget class deserialization.


9) Use of uninitialized resource (CVE-ID: CVE-2025-15281)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to usage of uninitialized resources when calling wordexp with WRDE_REUSE in conjunction with WRDE_APPEND. A remote attacker can pass specially crafted data to the application, trigger an uninitialized usage of resources and crash the application. 


10) Use of uninitialized resource (CVE-ID: CVE-2026-0915)

CWE-ID: CWE-908 - Use of Uninitialized Resource

CVSSv4: 2.1 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to usage of uninitialized resources when calling getnetbyaddr() or getnetbyaddr_r() functions with a configured nsswitch.conf and "net==0" in _nss_dns_getnetbyaddr_r. A remote attacker can trick the victim to initiate queries and force the library to leak contents to the configured DNS resolver. 


11) Reachable assertion (CVE-ID: CVE-2026-4046)

CWE-ID: CWE-617 - Reachable Assertion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to a reachable assertion in the iconv function when processing specially crafted input using the IBM1390 or IBM1399 character sets. A remote attacker can supply malicious input remotely to cause a denial of service.


12) Out-of-bounds write (CVE-ID: CVE-2026-5435)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 5.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to  deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write when printing TSIG records.. A remote attacker can create a specially crafted file, trick the victim into opening it using the affected software, trigger an out-of-bounds write and execute arbitrary code on the target system.


13) Buffer under-read (CVE-ID: CVE-2026-5928)

CWE-ID: CWE-127 - Buffer Under-read

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to calling the ungetwc function on a FILE stream with wide characters encoded in a character set that has overlaps between its single byte and multi-byte character encodings, in the GNU C Library may result in an attempt to read bytes before an allocated buffer. A remote attacker can pass specially crafted data to the application, causing disclosure of neighboring data in the heap, or a program crash.


14) Improper Certificate Validation (CVE-ID: CVE-2026-42011)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass name constraints during certificate validation.

The vulnerability exists due to improper certificate validation in the name constraints handling logic when processing certificate chains. A remote attacker can present a specially crafted certificate chain to bypass name constraints during certificate validation.

The issue occurs when permitted name constraints are ignored if prior certificate authorities contain only excluded name constraints.


15) Buffer Over-read (CVE-ID: CVE-2026-6238)

CWE-ID: CWE-126 - Buffer over-read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the target application or read uninitialized data.

The vulnerability exists due to deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.0.1 to version 2.43 fail to validate the RDATA content against the RDATA length in a DNS response when processing A6, CERT, LOC, TKEY or TSIG records. A remote attacker can craft a DNS response, causing a target application to crash or read uninitialized memory.


16) Resource exhaustion (CVE-ID: CVE-2025-14831)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources when verifying certificates with a large amount of name constraints. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


17) Double free (CVE-ID: CVE-2025-32988)

CWE-ID: CWE-415 - Double Free

CVSSv4: 7.5 [CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when exporting a certificate with an otherName in the SAN (subject alternative name) extension. A remote attacker can trick the victim into export a specially crafted certificate, trigger a double free error on the ASN.1 structure and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


18) NULL pointer dereference (CVE-ID: CVE-2025-32990)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when the certtool program is invoked with a template file with a number of string pairs for a single keyword. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


19) NULL pointer dereference (CVE-ID: CVE-2025-6395)

CWE-ID: CWE-476 - NULL Pointer Dereference

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error when a TLS 1.3 handshake involves a Hello Retry Request and the second Client Hello omits the PSK which was present in the first Client Hello. A remote attacker can pass specially crafted data to the application and perform a denial of service (DoS) attack.


20) Stack-based buffer overflow (CVE-ID: CVE-2025-9820)

CWE-ID: CWE-121 - Stack-based buffer overflow

CVSSv4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error within the gnutls_pkcs11_token_init() function in lib/pkcs11_write.c when initializing the PKCS#11 token. A local user can trigger a stack-based buffer overflow and execute arbitrary code on the target system.


21) Heap-based buffer overflow (CVE-ID: CVE-2026-33845)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service or execute arbitrary code.

The vulnerability exists due to a heap-based buffer overflow in the DTLS reassembly code when processing crafted DTLS fragments. A remote attacker can send specially crafted DTLS traffic to cause a denial of service or execute arbitrary code.


22) Heap-based buffer overflow (CVE-ID: CVE-2026-33846)

CWE-ID: CWE-122 - Heap-based Buffer Overflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a heap overwrite.

The vulnerability exists due to a heap-based buffer overflow in DTLS fragment handling when processing inconsistent DTLS fragments. A remote attacker can send specially crafted DTLS fragments to cause a heap overwrite.


23) Improper Certificate Validation (CVE-ID: CVE-2026-3833)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass name constraints validation.

The vulnerability exists due to improper certificate validation in name constraints processing when comparing domain names in certificates. A remote attacker can present a specially crafted certificate to bypass name constraints validation.

This issue affects excluded name constraints because domain name comparison was performed case-sensitively, contrary to RFC 5280 section 7.2.


24) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-42009)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper implementation of a qsort comparator contract in the DTLS packet sequence number comparator when ordering DTLS packets by sequence numbers. A remote attacker can send DTLS packets with duplicate sequence numbers to cause a denial of service.


25) XML External Entity injection (CVE-ID: CVE-2024-28757)

CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to insufficient validation of user-supplied XML input when using external parsers via XML_ExternalEntityParserCreate. A remote attacker can pass a specially crafted XML code to the affected application and view contents of arbitrary files on the system or initiate requests to external systems.

Successful exploitation of the vulnerability may allow an attacker to view contents of arbitrary file on the server or perform network scanning of internal and external infrastructure.


26) Improper Certificate Validation (CVE-ID: CVE-2026-42012)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to misuse certificates beyond their intended purpose.

The vulnerability exists due to improper certificate validation in certificate hostname verification when processing certificates containing URI or SRV Subject Alternative Names. A remote attacker can present a specially crafted certificate to misuse certificates beyond their intended purpose.

Certificates with URI or SRV Subject Alternative Names may incorrectly fall back to checking DNS hostnames against the Common Name.


27) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: CVE-2026-57818)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to obtain multiple valid access tokens from a single authorization code.

The vulnerability exists due to a race condition in JCacheCodeDataProvider when processing concurrent authorization code redemption requests. A remote attacker can send concurrent requests to obtain multiple valid access tokens from a single authorization code.


28) Use-after-free (CVE-ID: CVE-2026-42014)

CWE-ID: CWE-416 - Use After Free

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to use-after-free in gnutls_pkcs11_token_set_pin() when changing the Security Officer PIN with oldpin set to NULL for a token lacking a protected authentication path. A remote attacker can trigger the vulnerable function call to cause a denial of service.


29) Out-of-bounds write (CVE-ID: CVE-2026-42015)

CWE-ID: CWE-787 - Out-of-bounds write

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds write in the PKCS#12 bag handling code when appending to a PKCS#12 bag that already contains 32 elements. A remote attacker can supply crafted PKCS#12 data to cause a denial of service.


30) Out-of-bounds read (CVE-ID: CVE-2026-5260)

CWE-ID: CWE-125 - Out-of-bounds read

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in RSA key exchange handling when processing an extremely short premaster secret from a client for a server using an RSA key backed by a PKCS#11 token. A remote attacker can send a specially crafted premaster secret to disclose sensitive information.

Only servers using an RSA key backed by a PKCS#11 token are vulnerable.


31) Integer overflow (CVE-ID: CVE-2025-13601)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to crash the application.

The vulnerability exists due to integer overflow within the g_escape_uri_string() function. A remote attacker can pass specially crafted data to the application, trigger an integer overflow and perform a denial of service attack. 


32) Buffer overflow (CVE-ID: CVE-2025-14087)

CWE-ID: CWE-119 - Memory corruption

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error within the bytestring_parse() and string_parse() functions of the GVariant parser when processing maliciously crafted input strings. A remote attacker can pass specially crafted input to the application, trigger memory corruption and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


33) Integer overflow (CVE-ID: CVE-2025-14512)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to integer overflow within the GLib's GIO escape_byte_string() function when processing a malicious file or remote filesystem attribute values. A remote attacker can trick the victim into opening a specially crafted file, trigger an integer overflow and perform a denial of service attack. 


34) Integer underflow (CVE-ID: CVE-2026-58016)

CWE-ID: CWE-191 - Integer underflow

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to state confusion issue exists in g_dbus_node_info_new_for_xml() in the gio/gdbusintrospection.c file when processing malformed D-Bus introspection XML, specifically with a `node` element nested within other elements like `method`, `signal`, `property` or `arg`. A remote attacker can send a specially crafted request to the affected application, trigger an unsigned integer overflow and lead to an out-of-bounds read, resulting in a denial of service.


35) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-54225)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource control in attachment processing when handling large attachments without a configured maximum attachment size. A remote attacker can send a specially crafted request with a large attachment to cause a denial of service.

Only deployments that do not explicitly configure an attachment size limit are vulnerable.


36) Improper Authentication (CVE-ID: CVE-2026-57817)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to inject or substitute an authorization code.

The vulnerability exists due to improper authentication in the OIDC relying party hybrid flow implementation when processing hybrid flow responses from a non-compliant or misconfigured identity provider that omits the c_hash parameter. A remote attacker can supply a substituted authorization code to inject or substitute an authorization code.

Exploitation requires integration with an identity provider that omits the c_hash parameter in the hybrid OIDC flow.


37) Allocation of Resources Without Limits or Throttling (CVE-ID: CVE-2026-57819)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper resource allocation in the JAX-RS form parameter processing in cxf-rt-frontend-jaxrs when handling requests with very large numbers of form parameters. A remote attacker can send a specially crafted request to cause a denial of service.


38) Improper Certificate Validation (CVE-ID: CVE-2026-42013)

CWE-ID: CWE-295 - Improper Certificate Validation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass certificate hostname validation.

The vulnerability exists due to improper certificate validation in certificate Subject Alternative Name and Common Name hostname checking when validating certificates with oversized Subject Alternative Names. A remote attacker can present a specially crafted certificate to bypass certificate hostname validation.


39) Improper Authorization (CVE-ID: CVE-2026-61466)

CWE-ID: CWE-285 - Improper Authorization

CVSSv4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to self-assign privileged scopes.

The vulnerability exists due to improper access control in the OAuth2 Dynamic Client Registration endpoint when processing client registration requests. A remote user can submit a registration request with a crafted scope value to self-assign privileged scopes.


40) Input validation error (CVE-ID: CVE-2026-63687)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to undermine PKCE integrity and OpenID Connect replay protection.

The vulnerability exists due to improper input validation in JwtRequestCodeFilter when copying claims from a signed request JWT into the authorization parameter map. A remote user can provide a validly signed request JWT to override outer code_challenge, code_challenge_method, nonce, and state values to undermine PKCE integrity and OpenID Connect replay protection.

Exploitation requires the ability to produce a validly signed request JWT, such as when a client secret is known or compromised.


41) Input validation error (CVE-ID: CVE-2026-64958)

CWE-ID: CWE-20 - Improper input validation

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to improper input validation in message header attachment processing when handling messages with many attachment headers. A remote attacker can send a specially crafted message to cause a denial of service.


42) Resource exhaustion (CVE-ID: CVE-2026-50645)

CWE-ID: CWE-400 - Resource exhaustion

CVSSv4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to there is no restriction on the amount of attachment headers that a message can contain when being deserialized by Apache CXF. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.


43) XML External Entity injection (CVE-ID: CVE-2026-65432)

CWE-ID: CWE-611 - Improper Restriction of XML External Entity Reference ('XXE')

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to improper restriction of XML external entity references in WSDL4J import parsing when processing imported WSDL or XSD documents referenced by a top-level WSDL. A remote attacker can supply a specially crafted imported WSDL or XSD document to disclose sensitive information.

The issue affects imported documents referenced through <wsdl:import> or <xsd:import>, while the top-level WSDL is processed through a hardened parsing path.


44) Improper Authentication (CVE-ID: CVE-2026-65583)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to bypass authentication.

The vulnerability exists due to improper access control in the OIDC relying-party token validator when processing self-issued ID tokens. A remote attacker can supply a crafted token to bypass authentication.

Self-issued ID tokens are not accepted by default in the validator.


45) Deserialization of Untrusted Data (CVE-ID: CVE-2026-66909)

CWE-ID: CWE-502 - Deserialization of Untrusted Data

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.

The vulnerability exists due to unsafe deserialization in the JMS transport when processing an inbound JMS ObjectMessage. A remote attacker can place a malicious serialized object on the service's JMS destination to execute arbitrary code or cause a denial of service.

Remote code execution is possible if a suitable gadget class is present on the classpath.


46) Always-Incorrect Control Flow Implementation (CVE-ID: CVE-2026-68079)

CWE-ID: CWE-670 - Always-Incorrect Control Flow Implementation

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to redeem an authorization code multiple times.

The vulnerability exists due to improper authorization code invalidation in DefaultEncryptingCodeDataProvider when processing authorization code redemption. A remote attacker can reuse a captured authorization code to redeem an authorization code multiple times.

This issue violates the OAuth requirement that an authorization code must not be used more than once.


47) Improper access control (CVE-ID: CVE-2026-68481)

CWE-ID: CWE-284 - Improper Access Control

CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]


The vulnerability allows a remote user to continue using revoked OAuth tokens.

The vulnerability exists due to improper access control in DefaultEncryptingOAuthDataProvider and TokenIntrospectionService when processing revoked access or refresh tokens. A remote user can present a revoked token to continue using revoked OAuth tokens.

The issue affects both access tokens and refresh tokens, and token introspection may incorrectly report a revoked token as active.


48) Integer overflow (CVE-ID: CVE-2022-23990)

CWE-ID: CWE-190 - Integer overflow

CVSSv4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the doProlog() function. A remote attacker can pass specially crafted data to the application, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


49) Inefficient algorithmic complexity (CVE-ID: CVE-2026-45186)

CWE-ID: CWE-407 - Inefficient Algorithmic Complexity

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to perform a denial of service attack.

The vulnerability exists due to computational complexity of attribute name collision checks. A remote attacker can pass specially crafted XML input to the application and perform a denial of service attack.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.