Improper access control in Apache MINA - CVE-2026-41635
Published: April 28, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper access control in AbstractIoBuffer.resolveClass() when deserializing objects via IoBuffer.getObject(). A remote attacker can send a specially crafted serialized object to execute arbitrary code.
The issue affects the branch for static classes or primitive types, which bypasses the classname allowlist.
Affected software
Storage Defender Copy Data Management
IBM Sterling B2B Integrator
Datastax Enterprise with IBM
IBM Sterling File Gateway
openEuler
apache-mina-javadoc
apache-mina-mina-statemachine
apache-mina-mina-http
apache-mina-mina-filter-compression
apache-mina-mina-core
apache-mina
How to mitigate CVE-2026-41635
Storage Defender Copy Data Management - update to 2.3.1.0
IBM Sterling B2B Integrator - addressed in versions 6.2.0.6.1, 6.2.1.2, 6.2.2.1
IBM Sterling File Gateway - addressed in versions 6.2.0.6.1, 6.2.1.2, 6.2.2.1
apache-mina-javadoc - update to 2.1.11-1
apache-mina-mina-statemachine - update to 2.1.11-1
apache-mina-mina-http - update to 2.1.11-1
apache-mina-mina-filter-compression - update to 2.1.11-1
apache-mina-mina-core - update to 2.1.11-1
apache-mina - update to 2.1.11-1
Datastax Enterprise with IBM - update to 6.9.22
External References
Related Security Bulletins
- Multiple vulnerabilities in Apache MINA
- openEuler 24.03 LTS update for apache-mina
- openEuler 24.03 LTS SP3 update for apache-mina
- Multiple vulnerabilities in IBM DataStax Enterprise
- Multiple vulnerabilities in IBM Storage Defender Copy Data Management
- Multiple vulnerabilities in IBM Sterling B2B Integrator and IBM Sterling File Gateway