Deserialization of Untrusted Data in c3p0 - CVE-2026-27830
Published: April 22, 2026 / Updated: April 27, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to unsafe deserialization in the userOverridesAsString property of c3p0 ConnectionPoolDataSource implementations when processing maliciously crafted Java-serialized objects or javax.naming.Reference instances. A remote user can reset this property or supply crafted serialized objects or references to execute arbitrary code.
The impact can be amplified when embedded JNDI references trigger dereferencing of a remote factoryClassLocation.
Affected software
Crucible Server
Crucible Data Center
Crowd Data Center
IBM Qradar SIEM
Oracle Business Intelligence Enterprise Edition
MongoDB Enterprise Advanced with IBM
webMethods BPM
openSUSE Leap
openEuler
mchange-commons-javadoc
mchange-commons
c3p0
c3p0-help
c3p0-javadoc
release-notes-susemanager-proxy
release-notes-susemanager
Red Hat Camel for Spring Boot
How to mitigate CVE-2026-27830
Crucible Server - update to 4.9.9
Crucible Data Center - update to 4.9.9
Crowd Data Center - update to 7.2.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
MongoDB Enterprise Advanced with IBM - update to 8.0.22
webMethods BPM - update to 11.1 Fix 6
mchange-commons-javadoc - update to 0.2.20-150400.3.3.1
mchange-commons - update to 0.2.20-150400.3.3.1
c3p0 - update to 0.9.5.4-4
c3p0-help - update to 0.9.5.4-4
c3p0 - update to 0.9.5.5-150400.3.5.1
c3p0-javadoc - update to 0.9.5.5-150400.3.5.1
release-notes-susemanager-proxy - update to 4.3.17-150400.3.107.1
release-notes-susemanager - update to 4.3.17-150400.3.151.1
Red Hat Camel for Spring Boot - update to 4.14.4
External References
Related Security Bulletins
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- openEuler update for c3p0
- SUSE update for c3p0 and mchange-commons
- SUSE update for Maintenance update for Multi-Linux Manager 4.3 Release Notes Release Notes
- Remote code execution in c3p0
- IBM webMethods BPM update for c3p0
- Multiple vulnerabilities in Crucible Data Center and Crucible Server
- MongoDB Enterprise Advanced with IBM Ops-Manager update for c3p0
- Deserialization of Untrusted Data in Crowd Data Center
- Multiple vulnerabilities in IBM QRadar SIEM
- Multiple vulnerabilities in Red Hat Camel for Spring Boot 4.14