Deserialization of Untrusted Data in c3p0 - CVE-2026-27830

 

Deserialization of Untrusted Data in c3p0 - CVE-2026-27830

Published: April 22, 2026 / Updated: April 27, 2026


Vulnerability identifier: #VU126753
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27830
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to unsafe deserialization in the userOverridesAsString property of c3p0 ConnectionPoolDataSource implementations when processing maliciously crafted Java-serialized objects or javax.naming.Reference instances. A remote user can reset this property or supply crafted serialized objects or references to execute arbitrary code.

The impact can be amplified when embedded JNDI references trigger dereferencing of a remote factoryClassLocation.


Affected software

c3p0
Crucible Server
Crucible Data Center
Crowd Data Center
IBM Qradar SIEM
Oracle Business Intelligence Enterprise Edition
MongoDB Enterprise Advanced with IBM
webMethods BPM
openSUSE Leap
openEuler
mchange-commons-javadoc
mchange-commons
c3p0
c3p0-help
c3p0-javadoc
release-notes-susemanager-proxy
release-notes-susemanager
Red Hat Camel for Spring Boot

How to mitigate CVE-2026-27830

Install updates from vendor's website.

c3p0 - update to 0.12.0
Crucible Server - update to 4.9.9
Crucible Data Center - update to 4.9.9
Crowd Data Center - update to 7.2.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
MongoDB Enterprise Advanced with IBM - update to 8.0.22
webMethods BPM - update to 11.1 Fix 6
mchange-commons-javadoc - update to 0.2.20-150400.3.3.1
mchange-commons - update to 0.2.20-150400.3.3.1
c3p0 - update to 0.9.5.4-4
c3p0-help - update to 0.9.5.4-4
c3p0 - update to 0.9.5.5-150400.3.5.1
c3p0-javadoc - update to 0.9.5.5-150400.3.5.1
release-notes-susemanager-proxy - update to 4.3.17-150400.3.107.1
release-notes-susemanager - update to 4.3.17-150400.3.151.1
Red Hat Camel for Spring Boot - update to 4.14.4

External References

Related Security Bulletins