Improper access control in Apache MINA - CVE-2026-41635

 

Improper access control in Apache MINA - CVE-2026-41635

Published: April 28, 2026


Vulnerability identifier: #VU128405
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-41635
CWE-ID: CWE-284
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper access control in AbstractIoBuffer.resolveClass() when deserializing objects via IoBuffer.getObject(). A remote attacker can send a specially crafted serialized object to execute arbitrary code.

The issue affects the branch for static classes or primitive types, which bypasses the classname allowlist.


Affected software

Apache MINA
Storage Defender Copy Data Management
IBM Sterling B2B Integrator
Datastax Enterprise with IBM
IBM Sterling File Gateway
openEuler
apache-mina-javadoc
apache-mina-mina-statemachine
apache-mina-mina-http
apache-mina-mina-filter-compression
apache-mina-mina-core
apache-mina

How to mitigate CVE-2026-41635

Install security update from vendor's website.

Apache MINA - addressed in versions 2.0.28, 2.1.11, 2.2.6
Storage Defender Copy Data Management - update to 2.3.1.0
IBM Sterling B2B Integrator - addressed in versions 6.2.0.6.1, 6.2.1.2, 6.2.2.1
IBM Sterling File Gateway - addressed in versions 6.2.0.6.1, 6.2.1.2, 6.2.2.1
apache-mina-javadoc - update to 2.1.11-1
apache-mina-mina-statemachine - update to 2.1.11-1
apache-mina-mina-http - update to 2.1.11-1
apache-mina-mina-filter-compression - update to 2.1.11-1
apache-mina-mina-core - update to 2.1.11-1
apache-mina - update to 2.1.11-1
Datastax Enterprise with IBM - update to 6.9.22

External References

Related Security Bulletins